CVE-2010-4279: Critical severity pandora fms vulnerability
The default configuration of Pandora FMS 3.1 and earlier specifies an empty string for the loginhashpwd field, which allows remote attackers to bypass authentication by sending a request to index.php with "admin" in the loginhashuser parameter, in conjunction with the md5 hash of "admin" in the loginhashdata parameter.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2010-4279?
The severity of CVE-2010-4279 is considered high due to its ability to allow remote attackers to bypass authentication.
How do I fix CVE-2010-4279?
To fix CVE-2010-4279, ensure that the loginhash_pwd field is not set to an empty string and apply the latest updates from Pandora FMS.
What are the affected versions of Pandora FMS in CVE-2010-4279?
CVE-2010-4279 affects Pandora FMS versions 1.3 and earlier, up to version 3.1.
Can CVE-2010-4279 be exploited remotely?
Yes, CVE-2010-4279 can be exploited remotely by sending crafted requests to the vulnerable application.
What impact does CVE-2010-4279 have on systems?
CVE-2010-4279 allows unauthorized users to gain admin-level access to the Pandora FMS system, compromising its security.