Saturday, May 17, 2025
LBNN
  • Business
  • Markets
  • Politics
  • Crypto
  • Finance
  • Energy
  • Technology
  • Taxes
  • Creator Economy
  • Wealth Management
  • Documentaries
No Result
View All Result
LBNN

Positive Technologies helps eliminate critical vulnerabilities in Pandora FMS infrastructure monitoring software

Simon Osuji by Simon Osuji
June 12, 2024
in Telecoms
0
Positive Technologies helps eliminate critical vulnerabilities in Pandora FMS infrastructure monitoring software
0
SHARES
3
VIEWS
Share on FacebookShare on Twitter



Positive Technologies discovered four vulnerabilities in Pandora FMS, a Information Technology and Monitoring solutions provider. Over 50,000 companies across five continents rely on Pandora FMS to monitor their corporate networks, applications, servers, and other data sources. The vendor was notified of the vulnerabilities in line with the responsible disclosure policy and has already released software updates.

“Two SQL injection vulnerabilities (CVE-2023-44090 and CVE-2023-44091) were discovered in Pandora FMS. Attackers could read arbitrary data from the database, such as user sessions, without logging into the system. After reading the administrator session, an attacker could gain access to the administrator panel and exploit one of the two other vulnerabilities—creating an executable file outside the directory (Path Traversal, CVE-2023-41793) or executing commands in the operating system (OS Command Injection, CVE-2023-44092). This could lead to remote code execution on the server and its complete compromise. Next, the attacker could deploy miners on the server, gain access to private data, and escalate the attack to other hosts in the corporate network,” explains Alexey Solovyev, Positive Technologies Senior Application Security Specialist, who discovered these vulnerabilities.

The vulnerabilities, including CVE-2023-44090 (BDU:2024-03166), CVE-2023-44091 (BDU:2024-03165), CVE-2023-44092 (BDU:2024-03164), and CVE-2023-41793 (BDU:2024-03167), were rated 9.1 on the CVSS 3.0 scale, which indicates a critical level of severity.

To eliminate the vulnerabilities, it is necessary to update Pandora FMS to version NG 776 RRR or later.

The found vulnerabilities could have been detected as early as the product development stage by a static code analyzer like PT Application Inspector. To promptly identify vulnerabilities and prevent their exploitation (including SQL injection vulnerabilities, creating executable file outside the directory, and OS command injection), dynamic application analyzers such as PT BlackBox can help. Network traffic behavioral analysis systems also detect the exploitation of the mentioned vulnerabilities. For instance, PT Network Attack Discovery (PT NAD) detects attackers exploiting SQL injection, Path Traversal, and OS Command Injection vulnerabilities using detection rules 10010900, 10010901, 10010902, and 10010908. Web application firewalls, such as PT Application Firewall, and its cloud-based counterpart PT Cloud Application Firewall, also offer robust defense against these security weaknesses. To reduce the threat of remote code execution (RCE) at endpoints, including servers, endpoint detection and response (EDR) security solutions like MaxPatrol EDR can be used. Once malicious activity is detected, MaxPatrol EDR sends an alert to MaxPatrol SIEM and stops attackers in their tracks.

Previously, Alexey Solovyov helped eliminate vulnerabilities in the Nagios XI IT monitoring system, which could have led to the theft of private data and the hacking of network infrastructure.     

-Ends-

About Positive Technologies

Positive Technologies is an industry leader in results-oriented cybersecurity and a major global provider of information security solutions. Our mission is to safeguard businesses and entire industries against cyberattacks and non-tolerable damage. Over 4,000 organizations worldwide use technologies and services developed by our company. Positive Technologies is the first and only cybersecurity company in Russia to have gone public on the Moscow Exchange (MOEX: POSI), with 205,000 shareholders and counting. Follow us in the News section at ptsecurity.com.



Source link

Related posts

African Development Bank approves $304mln loan to support Botswana’s fiscal stability and economic reforms

African Development Bank approves $304mln loan to support Botswana’s fiscal stability and economic reforms

May 17, 2025
KFSHRC and Cleveland Clinic partner to drive innovation in autism and neuroscience

KFSHRC and Cleveland Clinic partner to drive innovation in autism and neuroscience

May 17, 2025
Previous Post

Deepfakes threaten upcoming elections, but ‘responsible AI’ could help filter them out before they reach us

Next Post

At last, Apple’s Messages app will support RCS and scheduling texts

Next Post
At last, Apple’s Messages app will support RCS and scheduling texts

At last, Apple's Messages app will support RCS and scheduling texts

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

RECOMMENDED NEWS

10 African countries with the lowest budget allocation for education

10 African countries with the lowest budget allocation for education

6 months ago
Lithuania Moves to Quit Convention on Cluster Munitions

Lithuania Moves to Quit Convention on Cluster Munitions

10 months ago
Why Monitoring At Landfills Is Vital To Keeping Groundwater Clean

Why Monitoring At Landfills Is Vital To Keeping Groundwater Clean

1 week ago
US Air Force Tests Boeing Modular Weapons Pylon on B-1

US Air Force Tests Boeing Modular Weapons Pylon on B-1

9 months ago

POPULAR NEWS

  • Ghana to build three oil refineries, five petrochemical plants in energy sector overhaul

    Ghana to build three oil refineries, five petrochemical plants in energy sector overhaul

    0 shares
    Share 0 Tweet 0
  • When Will SHIB Reach $1? Here’s What ChatGPT Says

    0 shares
    Share 0 Tweet 0
  • Matthew Slater, son of Jackson State great, happy to see HBCUs back at the forefront

    0 shares
    Share 0 Tweet 0
  • Dolly Varden Focuses on Adding Ounces the Remainder of 2023

    0 shares
    Share 0 Tweet 0
  • US Dollar Might Fall To 96-97 Range in March 2024

    0 shares
    Share 0 Tweet 0
  • Privacy Policy
  • Contact

© 2023 LBNN - All rights reserved.

No Result
View All Result
  • Home
  • Business
  • Politics
  • Markets
  • Crypto
  • Economics
    • Manufacturing
    • Real Estate
    • Infrastructure
  • Finance
  • Energy
  • Creator Economy
  • Wealth Management
  • Taxes
  • Telecoms
  • Military & Defense
  • Careers
  • Technology
  • Artificial Intelligence
  • Investigative journalism
  • Art & Culture
  • Documentaries
  • Quizzes
    • Enneagram quiz
  • Newsletters
    • LBNN Newsletter
    • Divergent Capitalist

© 2023 LBNN - All rights reserved.