CVE-2024-41954: FOG Weak file permissions
FOG is a cloning/imaging/rescue suite/inventory management system. The application stores plaintext service account credentials in the "/opt/fog/.fogsettings" file. This file is by default readable by all users on the host. By exploiting these credentials, a malicious user could create new accounts for the web application and much more. The vulnerability is fixed in 1.5.10.41.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2024-41954?
CVE-2024-41954 has a high severity due to the exposure of plaintext service account credentials.
How do I fix CVE-2024-41954?
To fix CVE-2024-41954, you should secure access to the "/opt/fog/.fogsettings" file by changing its permissions to restrict read access.
What are the potential impacts of CVE-2024-41954?
The potential impacts of CVE-2024-41954 include unauthorized access to the FOG application and possible exploitation of the service account credentials.
Which versions of FOG are affected by CVE-2024-41954?
CVE-2024-41954 affects versions of the FOG application from 1.5.10 to 1.5.10.41.
Is there a patch available for CVE-2024-41954?
Yes, a patch for CVE-2024-41954 is available in the upcoming releases of the FOG application.