CVE-2024-11320
moderateCommand Injection in Pandora FMS LDAP Authentication Enables Arbitrary Command Execution
CVE-2024-11320 is a command injection flaw (CWE-77) in the LDAP authentication mechanism of the Pandora FMS monitoring platform, allowing arbitrary commands to be executed on the server. It affects Pandora FMS versions 700 through 777.4 and, per the CVSS 4.0 vector, is reachable over the network with low attack complexity, but requires the attacker to already hold high-privileged (administrator-level) access. Successful exploitation primarily compromises the integrity of the target system through arbitrary command execution, with limited confidentiality and availability impact per the scoring. Only deployments that use LDAP authentication are exposed to this specific flaw. There is no known public proof-of-concept or CISA KEV listing yet, but EPSS assigns a 91% probability of exploitation within 30 days (100th percentile), so defenders should patch promptly despite no confirmed in-the-wild exploitation.
What to do: Upgrade all Pandora FMS deployments running versions 700 through 777.4 to a release newer than 777.4 per the vendor advisory (the available data does not specify a fixed version number). Deployments that cannot patch promptly should verify whether LDAP authentication is enabled and, if so, disable or restrict it (e.g., limit administrative access to trusted sources) since only LDAP-based deployments are exploitable. Administrators should also audit privileged accounts and server logs for signs of unexpected command execution.
| Pandora FMS | 700 through 777.4 (inclusive) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Arbitrary commands execution on the server by exploiting a command injection vulnerability in the LDAP authentication mechanism. This issue affects Pandora FMS: from 700 through <=777.4
- Vendors
- pandorafms
- Products
- pandora fms
- Weakness
- CWE-77
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:H/VA:L/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:N/R:U/V:C/RE:M/U:Amber
In the news0 stories
No ingested article mentions this CVE yet.