Vulnerability Description
FOG is a cloning/imaging/rescue suite/inventory management system. The application stores plaintext service account credentials in the "/opt/fog/.fogsettings" file. This file is by default readable by all users on the host. By exploiting these credentials, a malicious user could create new accounts for the web application and much more. The vulnerability is fixed in 1.5.10.41.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fogproject | Fogproject | >= 1.5.10, <= 1.5.10.41 |
Related Weaknesses (CWE)
References
- https://github.com/FOGProject/fogproject/commit/97ed6d51608e52fc087ca1d2f03d6b8dPatch
- https://github.com/FOGProject/fogproject/security/advisories/GHSA-pcqm-h8cx-282cExploitVendor Advisory
FAQ
What is CVE-2024-41954?
CVE-2024-41954 is a vulnerability with a CVSS score of 5.3 (MEDIUM). FOG is a cloning/imaging/rescue suite/inventory management system. The application stores plaintext service account credentials in the "/opt/fog/.fogsettings" file. This file is by default readable by...
How severe is CVE-2024-41954?
CVE-2024-41954 has been rated MEDIUM with a CVSS base score of 5.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-41954?
Check the references section above for vendor advisories and patch information. Affected products include: Fogproject Fogproject.