CVE-2024-35308: Post-auth Arbitrary File Read in the Server Plugins Section
Published Oct 22, 2024
·Updated
A post-authentication arbitrary file read vulnerability within the server plugins section in plugin edition feature. This issue affects Pandora FMS: from 700 through <777.3.
Affected Software
1 affected component
PandoraFMS Pandora FMS>=700<777.3
Remediation
Information
Update to v777.3
Event History
Oct 22, 2024
CVE Published
via MITRE·09:03 AM
Data Sourced
via MITRE·09:03 AM
RemedyDescriptionWeakness
Data Sourced
via NVD·09:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-35308?
CVE-2024-35308 is classified as a moderate severity vulnerability.
2
How do I fix CVE-2024-35308?
To fix CVE-2024-35308, update Pandora FMS to a version later than 777.3.
3
What type of vulnerability is CVE-2024-35308?
CVE-2024-35308 is a post-authentication arbitrary file read vulnerability.
4
Which versions of Pandora FMS are affected by CVE-2024-35308?
CVE-2024-35308 affects Pandora FMS versions from 700 to 777.3.
5
Can CVE-2024-35308 be exploited remotely?
CVE-2024-35308 requires authentication, so it cannot be exploited remotely without valid credentials.