First published: Fri May 07 2021(Updated: )
Artica Pandora FMS 742 allows unauthenticated attackers to perform Phar deserialization.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Artica Pandora FMS | =742 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-32098 is a vulnerability in Artica Pandora FMS 742 that allows unauthenticated attackers to perform Phar deserialization.
CVE-2021-32098 has a severity rating of 9.8, which is considered critical.
Unauthenticated attackers can exploit CVE-2021-32098 by performing Phar deserialization.
Yes, make sure to update Artica Pandora FMS to a version that is not affected by this vulnerability.
You can find more information about CVE-2021-32098 in the provided references: https://blog.sonarsource.com/pandora-fms-742-critical-code-vulnerabilities-explained, https://pandorafms.com/blog/whats-new-in-pandora-fms-743/, and https://portswigger.net/daily-swig/multiple-vulnerabilities-in-pandora-fms-could-trigger-remote-execution-attack.