FOG is a cloning/imaging/rescue suite/inventory management system. FOG Server 1.5.10.41.2 can leak AD username and password when registering a computer. This vulnerability is fixed in 1.5.10.41.3 and 1.6.0-beta.1395.
The vulnerability classified as command injection (CWE-77) causes the FOG server to disclose Active Directory login credentials during the registration of a new computer on the network. Since the registration process is available over the network without authentication (vector AV:N, PR:N), an attacker can trigger this operation remotely and intercept the transmitted or displayed AD credentials.
An attacker gains access to the username and password of the Active Directory account used by the FOG server, which may lead to compromise of domain accounts and further lateral movement in the organization's infrastructure.
FOG Server should be updated to version 1.5.10.41.3 or 1.6.0-beta.1395, in which the vulnerability has been fixed. Details are available in the official FOGProject security advisory on GitHub.
FOG Server version 1.5.10.41.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:NFogproject
APPFogproject1.5.10.41 – 1.5.10.41.3 (excl.)
Related vulnerabilities
FOG Project – pomijanie uwierzytelnienia umożliwia zrzut bazy danych
Command injection w FOGProject przez parametr filename w export.php
FOG Project: Stored XSS przez pole sysproduct w module inwentaryzacji
FOG Project – stored XSS w niezabezpieczonym endpoincie inventory
FOG Project: nieuwierzytelniony dostęp do metod clearAES i clearPMTasks