CyberRota Analysis
AI-GeneratedFOG's cloning and imaging system is vulnerable to unauthenticated remote access, allowing attackers to execute the `clearAES` and `clearPMTasks` methods via a simple HTTP GET request. This exploit can lead to the remote wiping of AES encryption credentials and deletion of scheduled power management tasks, posing a significant risk to system integrity. Organizations using affected versions should prioritize upgrading to versions 1.5.10.1832 or 1.6.0-beta.2313 to mitigate this high-severity vulnerability.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
FOG is a free open-source cloning/imaging/rescue suite/inventory management system. Prior to versions 1.5.10.1832 and 1.6.0-beta.2313, the `clearAES` and `clearPMTasks` methods in `FOGPage` can be invoked by an unauthenticated attacker via a single HTTP GET request through the public `client` node endpoint. This allows remote wiping of host AES encryption credentials and deletion of all power management scheduled tasks, with no login, session, or CSRF token required. Versions 1.5.10.1832 and 1.6.0-beta.2313 fix the issue.
Related CVEs
Other vulnerabilities affecting the same vendor(s)