CVE-2021-32098: Critical severity pandora fms vulnerability
Artica Pandora FMS 742 allows unauthenticated attackers to perform Phar deserialization.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-32098?
CVE-2021-32098 is a vulnerability in Artica Pandora FMS 742 that allows unauthenticated attackers to perform Phar deserialization.
How severe is CVE-2021-32098?
CVE-2021-32098 has a severity rating of 9.8, which is considered critical.
How can unauthenticated attackers exploit CVE-2021-32098?
Unauthenticated attackers can exploit CVE-2021-32098 by performing Phar deserialization.
Is there a fix for CVE-2021-32098?
Yes, make sure to update Artica Pandora FMS to a version that is not affected by this vulnerability.
Where can I find more information about CVE-2021-32098?
You can find more information about CVE-2021-32098 in the provided references: https://blog.sonarsource.com/pandora-fms-742-critical-code-vulnerabilities-explained, https://pandorafms.com/blog/whats-new-in-pandora-fms-743/, and https://portswigger.net/daily-swig/multiple-vulnerabilities-in-pandora-fms-could-trigger-remote-execution-attack.