CVE-2022-26308
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
01/08/2022
Last modified:
05/08/2022
Description
Pandora FMS v7.0NG.760 and below allows an improper access control in Configuration (Credential store) where a user with the role of Operator (Write) could create, delete, view existing keys which are outside the intended role.
Impact
Base Score 3.x
5.40
Severity 3.x
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:pandorafms:pandora_fms:*:*:*:*:*:*:*:* | 7.0_ng_760 (including) |
To consult the complete list of CPE names with products and versions, see this page



