CVE Feed

    Dashboard / CVE / CVE-2024-41954

    CVE-2024-41954

    FOG is a cloning/imaging/rescue suite/inventory management system. The application stores plaintext service account credentials in the "/opt/fog/.fogsettings" file. This file is by default readable by all users on the host. By exploiting these credentials, a malicious user could create new accounts for the web application and much more. The vulnerability is fixed in 1.5.10.41.

    Published:Jul 31, 2024
    Last Modified:Sep 5, 2024
    EPS:Jul 31, 2024
    EPSS Score:0.00075
    CVSS Score:5.3

    Affected Products

    Vendor
    Fogproject
    Product
    Fogproject

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High