AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2022-43978

MEDIUM · CVSS 5.6 EPSS 0.30%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2023-01-27 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

CVE
CVE-2022-43978
Severity
MEDIUM
CVSS
5.6
EPSS
0.30%

Original NVD Description

There is an improper authentication vulnerability in Pandora FMS v764. The application verifies that the user has a valid session when he is not trying to do a login. Since the secret is static in generatePublicHash function, an attacker with knowledge of a valid session can abuse this in order to pass the authentication check.