Description
Authentication Bypass by Spoofing vulnerability in the password reset process of Pandora FMS allows an unauthenticated attacker to initiate a password reset process for any user account without proper authentication. This issue affects PandoraFMS v771 and prior versions on all platforms.
Published: 2023-06-13
Score: 6.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Solution

Fixed in v772

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-34260 Authentication Bypass by Spoofing vulnerability in the password reset process of Pandora FMS allows an unauthenticated attacker to initiate a password reset process for any user account without proper authentication. This issue affects PandoraFMS v771 and prior versions on all platforms.
History

Fri, 03 Jan 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Pandorafms Pandora Fms
cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2025-01-03T15:22:20.936Z

Reserved: 2023-05-19T08:29:18.021Z

Link: CVE-2023-2807

cve-icon Vulnrichment

Updated: 2024-08-02T06:33:05.503Z

cve-icon NVD

Status : Modified

Published: 2023-06-13T12:15:09.380

Modified: 2024-11-21T07:59:19.733

Link: CVE-2023-2807

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses