-
Notifications
You must be signed in to change notification settings - Fork 14.1k
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Pandora FMS auth RCE [CVE-2024-11320] #19738
base: master
Are you sure you want to change the base?
Conversation
Hi @h00die-gr3y, I noticed that both the file name and the module title mention |
modules/exploits/linux/http/pandora_fms_preauth_rce_cve_2024_11320.rb
Outdated
Show resolved
Hide resolved
modules/exploits/linux/http/pandora_fms_preauth_rce_cve_2024_11320.rb
Outdated
Show resolved
Hide resolved
modules/exploits/linux/http/pandora_fms_preauth_rce_cve_2024_11320.rb
Outdated
Show resolved
Hide resolved
modules/exploits/linux/http/pandora_fms_preauth_rce_cve_2024_11320.rb
Outdated
Show resolved
Hide resolved
modules/exploits/linux/http/pandora_fms_preauth_rce_cve_2024_11320.rb
Outdated
Show resolved
Hide resolved
Thanks for your pull request! Before this can be merged, we need the following documentation for your module: |
Done. See 2abde4c. |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Thanks @h00die-gr3y, I have submitted few comments to the code, the exploit is functional though. Also, can you please submit documentation for the module?
modules/exploits/linux/http/pandora_fms_auth_rce_cve_2024_11320.rb
Outdated
Show resolved
Hide resolved
Dear Reviewers, Finally, the command injection vulnerability (GHSA-882x-5jhv-r9x4) in the LDAP authentication mechanism of Pandora FMS did not work for versions lower then Documentation will be provided over the weekend. |
Last one for this year ;-)
Pandora FMS is a monitoring solution that provides full observability for your organization's technology.
This module exploits an command injection vulnerability (CVE-2024-11320) in the LDAP authentication mechanism of Pandora FMS.
You need have admin access at the Pandora FMS Web application in order to execute this RCE.
This access can be achieved leveraging a default password weakness in Pandora FMS that allows an attacker to access the Pandora FMS MySQL database, create a new admin user and gain administrative access to the Pandora FMS Web application.
The attack can be remotely executed over the WAN as long as the MySQL services are exposed to the outside world.
This issue affects Pandora FMS Community, Free and Enterprise edition: from
718
through <=777.4