CRITICAL🇵🇱 Wersja polska

CVE-2024-42348

CVSS 9.3v3.1pub. 2024-08-02upd. 2024-09-10

FOG is a cloning/imaging/rescue suite/inventory management system. FOG Server 1.5.10.41.2 can leak AD username and password when registering a computer. This vulnerability is fixed in 1.5.10.41.3 and 1.6.0-beta.1395.

🤖 AI Analysis
How it works

The vulnerability classified as command injection (CWE-77) causes the FOG server to disclose Active Directory login credentials during the registration of a new computer on the network. Since the registration process is available over the network without authentication (vector AV:N, PR:N), an attacker can trigger this operation remotely and intercept the transmitted or displayed AD credentials.

Impact

An attacker gains access to the username and password of the Active Directory account used by the FOG server, which may lead to compromise of domain accounts and further lateral movement in the organization's infrastructure.

Mitigation & patch

FOG Server should be updated to version 1.5.10.41.3 or 1.6.0-beta.1395, in which the vulnerability has been fixed. Details are available in the official FOGProject security advisory on GitHub.

Who is affected

FOG Server version 1.5.10.41.2

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
  • Fogproject

    APP
    Fogproject
    1.5.10.41 – 1.5.10.41.3 (excl.)
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References

Related vulnerabilities

CVE-2025-58443CRITICAL9.9PL ✓same product

FOG Project – pomijanie uwierzytelnienia umożliwia zrzut bazy danych

CVE-2024-39914CRITICAL9.8PL ✓same product

Command injection w FOGProject przez parametr filename w export.php

CVE-2026-47687HIGH7.3PL ✓same product

FOG Project: Stored XSS przez pole sysproduct w module inwentaryzacji

CVE-2026-47685HIGH7.3PL ✓same product

FOG Project – stored XSS w niezabezpieczonym endpoincie inventory

CVE-2026-47688HIGH8.2PL ✓same product

FOG Project: nieuwierzytelniony dostęp do metod clearAES i clearPMTasks