HIGH · 10.0

CVE-2010-4279

The default configuration of Pandora FMS 3.1 and earlier specifies an empty string for the loginhash_pwd field, which allows remote attackers to bypass authentication by sending a request to index.php...

Vulnerability Description

The default configuration of Pandora FMS 3.1 and earlier specifies an empty string for the loginhash_pwd field, which allows remote attackers to bypass authentication by sending a request to index.php with "admin" in the loginhash_user parameter, in conjunction with the md5 hash of "admin" in the loginhash_data parameter.

CVSS Score

10.0

HIGH

AV:N/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
ArticaPandora Fms<= 3.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2010-4279?

CVE-2010-4279 is a vulnerability with a CVSS score of 10.0 (HIGH). The default configuration of Pandora FMS 3.1 and earlier specifies an empty string for the loginhash_pwd field, which allows remote attackers to bypass authentication by sending a request to index.php...

How severe is CVE-2010-4279?

CVE-2010-4279 has been rated HIGH with a CVSS base score of 10.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2010-4279?

Check the references section above for vendor advisories and patch information. Affected products include: Artica Pandora Fms.