CVE-2024-42348: FOG leaks sensitive information (AD domain, username and password)
Published Aug 2, 2024
·Updated
FOG is a cloning/imaging/rescue suite/inventory management system. FOG Server 1.5.10.41.2 can leak AD username and password when registering a computer. This vulnerability is fixed in 1.5.10.41.3 and 1.6.0-beta.1395.
Affected Software
1 affected component
fogproject fogproject>=1.5.10.41<1.5.10.41.3
Event History
Aug 2, 2024
CVE Published
via MITRE·07:58 PM
Data Sourced
via MITRE·07:58 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-42348?
CVE-2024-42348 is a medium severity vulnerability related to credential leakage.
2
How can I fix CVE-2024-42348?
To fix CVE-2024-42348, update your FOG Server to version 1.5.10.41.3 or 1.6.0-beta.1395.
3
What systems are affected by CVE-2024-42348?
CVE-2024-42348 affects FOG Server versions prior to 1.5.10.41.3.
4
What information is leaked in CVE-2024-42348?
CVE-2024-42348 can leak Active Directory usernames and passwords during the computer registration process.
5
Is there a permanent solution to CVE-2024-42348?
Yes, the permanent solution is to upgrade to the latest versions of FOG Server indicated in the vulnerability fix.