CVE-2023-2807: Authentication bypass in password reset process
Authentication Bypass by Spoofing vulnerability in the password reset process of Pandora FMS allows an unauthenticated attacker to initiate a password reset process for any user account without proper authentication. This issue affects PandoraFMS v771 and prior versions on all platforms.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-2807?
CVE-2023-2807 is an Authentication Bypass by Spoofing vulnerability in the password reset process of Pandora FMS.
How does CVE-2023-2807 impact Pandora FMS?
CVE-2023-2807 allows an unauthenticated attacker to initiate a password reset process for any user account without proper authentication.
Which versions of Pandora FMS are affected by CVE-2023-2807?
PandoraFMS v771 and prior versions on all platforms are affected by CVE-2023-2807.
What is the severity of CVE-2023-2807?
CVE-2023-2807 has a severity rating of 9.8 (Critical).
How can I fix CVE-2023-2807?
There is no known fix or patch available for CVE-2023-2807 at the moment. It is recommended to monitor the vendor's website for updates or follow any provided mitigation steps.