• Business
  • Markets
  • Politics
  • Crypto
  • Finance
  • Intelligence
    • Policy Intelligence
    • Security Intelligence
    • Economic Intelligence
    • Fashion Intelligence
  • Energy
  • Technology
  • Taxes
  • Creator Economy
  • Wealth Management
  • LBNN Blueprints
  • Business
  • Markets
  • Politics
  • Crypto
  • Finance
  • Intelligence
    • Policy Intelligence
    • Security Intelligence
    • Economic Intelligence
    • Fashion Intelligence
  • Energy
  • Technology
  • Taxes
  • Creator Economy
  • Wealth Management
  • LBNN Blueprints

Positive Technologies helps eliminate critical vulnerabilities in Pandora FMS infrastructure monitoring software

Simon Osuji by Simon Osuji
June 12, 2024
in Telecoms
0
Positive Technologies helps eliminate critical vulnerabilities in Pandora FMS infrastructure monitoring software
0
SHARES
4
VIEWS
Share on FacebookShare on Twitter



Positive Technologies discovered four vulnerabilities in Pandora FMS, a Information Technology and Monitoring solutions provider. Over 50,000 companies across five continents rely on Pandora FMS to monitor their corporate networks, applications, servers, and other data sources. The vendor was notified of the vulnerabilities in line with the responsible disclosure policy and has already released software updates.

“Two SQL injection vulnerabilities (CVE-2023-44090 and CVE-2023-44091) were discovered in Pandora FMS. Attackers could read arbitrary data from the database, such as user sessions, without logging into the system. After reading the administrator session, an attacker could gain access to the administrator panel and exploit one of the two other vulnerabilities—creating an executable file outside the directory (Path Traversal, CVE-2023-41793) or executing commands in the operating system (OS Command Injection, CVE-2023-44092). This could lead to remote code execution on the server and its complete compromise. Next, the attacker could deploy miners on the server, gain access to private data, and escalate the attack to other hosts in the corporate network,” explains Alexey Solovyev, Positive Technologies Senior Application Security Specialist, who discovered these vulnerabilities.

The vulnerabilities, including CVE-2023-44090 (BDU:2024-03166), CVE-2023-44091 (BDU:2024-03165), CVE-2023-44092 (BDU:2024-03164), and CVE-2023-41793 (BDU:2024-03167), were rated 9.1 on the CVSS 3.0 scale, which indicates a critical level of severity.

To eliminate the vulnerabilities, it is necessary to update Pandora FMS to version NG 776 RRR or later.

The found vulnerabilities could have been detected as early as the product development stage by a static code analyzer like PT Application Inspector. To promptly identify vulnerabilities and prevent their exploitation (including SQL injection vulnerabilities, creating executable file outside the directory, and OS command injection), dynamic application analyzers such as PT BlackBox can help. Network traffic behavioral analysis systems also detect the exploitation of the mentioned vulnerabilities. For instance, PT Network Attack Discovery (PT NAD) detects attackers exploiting SQL injection, Path Traversal, and OS Command Injection vulnerabilities using detection rules 10010900, 10010901, 10010902, and 10010908. Web application firewalls, such as PT Application Firewall, and its cloud-based counterpart PT Cloud Application Firewall, also offer robust defense against these security weaknesses. To reduce the threat of remote code execution (RCE) at endpoints, including servers, endpoint detection and response (EDR) security solutions like MaxPatrol EDR can be used. Once malicious activity is detected, MaxPatrol EDR sends an alert to MaxPatrol SIEM and stops attackers in their tracks.

Previously, Alexey Solovyov helped eliminate vulnerabilities in the Nagios XI IT monitoring system, which could have led to the theft of private data and the hacking of network infrastructure.     

-Ends-

About Positive Technologies

Positive Technologies is an industry leader in results-oriented cybersecurity and a major global provider of information security solutions. Our mission is to safeguard businesses and entire industries against cyberattacks and non-tolerable damage. Over 4,000 organizations worldwide use technologies and services developed by our company. Positive Technologies is the first and only cybersecurity company in Russia to have gone public on the Moscow Exchange (MOEX: POSI), with 205,000 shareholders and counting. Follow us in the News section at ptsecurity.com.



Source link

Related posts

Mideast crude premiums spike on Iran war, Platts Dubai change

Mideast crude premiums spike on Iran war, Platts Dubai change

March 7, 2026
Kuwait has begun cutting production at some oil fields, WSJ reports

Kuwait has begun cutting production at some oil fields, WSJ reports

March 7, 2026
Previous Post

Deepfakes threaten upcoming elections, but ‘responsible AI’ could help filter them out before they reach us

Next Post

At last, Apple’s Messages app will support RCS and scheduling texts

Next Post
At last, Apple’s Messages app will support RCS and scheduling texts

At last, Apple's Messages app will support RCS and scheduling texts

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

RECOMMENDED NEWS

Border Biennial showcases art across the Texas-Mexico border

Border Biennial showcases art across the Texas-Mexico border

2 years ago
In the Democratic Republic of the Congo (DRC), mobile courts fight impunity and bring dignity to victims

In the Democratic Republic of the Congo (DRC), mobile courts fight impunity and bring dignity to victims

1 year ago
2026 to be the year of the agentic AI intern

2026 to be the year of the agentic AI intern

2 months ago
Saudi Arabia announces strict Makkah entry rules for Hajj 2025: Report

Saudi Arabia announces strict Makkah entry rules for Hajj 2025: Report

11 months ago

POPULAR NEWS

  • Mahama attends Liberia’s 178th independence anniversary

    Mahama attends Liberia’s 178th independence anniversary

    0 shares
    Share 0 Tweet 0
  • Ghana to build three oil refineries, five petrochemical plants in energy sector overhaul

    0 shares
    Share 0 Tweet 0
  • The world’s top 10 most valuable car brands in 2025

    0 shares
    Share 0 Tweet 0
  • Top 10 African countries with the highest GDP per capita in 2025

    0 shares
    Share 0 Tweet 0
  • Global ranking of Top 5 smartphone brands in Q3, 2024

    0 shares
    Share 0 Tweet 0

Get strategic intelligence you won’t find anywhere else. Subscribe to the Limitless Beliefs Newsletter for monthly insights on overlooked business opportunities across Africa.

Subscription Form

© 2026 LBNN – All rights reserved.

Privacy Policy | About Us | Contact

Tiktok Youtube Telegram Instagram Linkedin X-twitter
No Result
View All Result
  • Home
  • Business
  • Politics
  • Markets
  • Crypto
  • Economics
    • Manufacturing
    • Real Estate
    • Infrastructure
  • Finance
  • Energy
  • Creator Economy
  • Wealth Management
  • Taxes
  • Telecoms
  • Military & Defense
  • Careers
  • Technology
  • Artificial Intelligence
  • Investigative journalism
  • Art & Culture
  • LBNN Blueprints
  • Quizzes
    • Enneagram quiz
  • Fashion Intelligence

© 2023 LBNN - All rights reserved.