CVE-2022-43978 - CVE House
Back to Database
Status published Medium CVE-2022-43978

Limited Authentication bypass due to hardcoded secret

Vulnerability Description

There is an improper authentication vulnerability in Pandora FMS v764. The application verifies that the user has a valid session when he is not trying to do a login. Since the secret is static in generatePublicHash function, an attacker with knowledge of a valid session can abuse this in order to pass the authentication check.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2022-43978

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Artica PFMS

View all reports →

Affected Software

Pandora FMS
Vulnerable Versions:
v764

Timeline

Official Publish: January 27th, 2023
Last Modified: March 27th, 2025
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:A/AC:H/PR:H/UI:R/S:U/C:H/I:H/A:N

Weaknesses (CWE)