CVE-2023-24517
Remote Code Execution via Unrestricted File Upload
Severity Score
7.2
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
2
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
Attend
*SSVC
Descriptions
Unrestricted Upload of File with Dangerous Type vulnerability in the Pandora FMS File Manager component, allows an attacker to make make use of this issue ( unrestricted file upload ) to execute arbitrary system commands. This issue affects Pandora FMS v767 version and prior versions on all platforms.
Vulnerabilidad de subida no restringida de ficheros de tipo peligroso en el componente "File Manager" de Pandora FMS, podría permite a un atacante hacer uso de este problema (subida no restringida de ficheros) para ejecutar comandos arbitrarios del sistema. Este problema afecta a la versión Pandora FMS v767 y anteriores en todas las plataformas.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Attend
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2023-01-25 CVE Reserved
- 2023-08-22 CVE Published
- 2023-10-15 First Exploit
- 2024-08-28 EPSS Updated
- 2024-10-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-434: Unrestricted Upload of File with Dangerous Type
CAPEC
- CAPEC-1: Accessing Functionality Not Properly Constrained by ACLs
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://github.com/Argonx21/CVE-2023-24517 | 2023-10-15 | |
https://gist.github.com/Argonx21/9ab62f6e5d8bc6d39b8a338426af121e | 2024-10-03 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://pandorafms.com/en/security/common-vulnerabilities-and-exposures | 2023-11-02 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Pandorafms Search vendor "Pandorafms" | Pandora Fms Search vendor "Pandorafms" for product "Pandora Fms" | <= 767 Search vendor "Pandorafms" for product "Pandora Fms" and version " <= 767" | - |
Affected
|