Vulnerability Details CVE-2024-41954
FOG is a cloning/imaging/rescue suite/inventory management system. The application stores plaintext service account credentials in the "/opt/fog/.fogsettings" file. This file is by default readable by all users on the host. By exploiting these credentials, a malicious user could create new accounts for the web application and much more. The vulnerability is fixed in 1.5.10.41.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 1.7%
CVSS Severity
CVSS v3 Score 5.3
Products affected by CVE-2024-41954
-
cpe:2.3:a:fogproject:fogproject:1.5.10
-
cpe:2.3:a:fogproject:fogproject:1.5.10.15
-
cpe:2.3:a:fogproject:fogproject:1.5.10.30
-
cpe:2.3:a:fogproject:fogproject:1.5.10.41