CVE-2024-35308
Pandorafms
CVE-2024-35308 is a high-severity vulnerability affecting Pandora FMS, allowing arbitrary file read after authentication. This vulnerability, present in versions 700 up to but not including 777.3, arises from insufficient path validation in the server plugins section of the plugin edition feature. The vulnerability could be exploited by an authenticated attacker to read sensitive files on the server.
While the CVSS score is 8.8, SOCRadar's SVRS of 77 indicates a significant, though not critical, risk. Given that CVE-2024-35308 is tagged as "In The Wild," immediate patching is strongly advised, despite the SVRS being just below the critical threshold of 80. Successful exploitation grants unauthorized access to potentially sensitive information, including configuration files, source code, and credentials, which could lead to further system compromise.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.