ZeroHour

CVE-2024-11320

moderate

Command Injection in Pandora FMS LDAP Authentication Enables Arbitrary Command Execution

CVSS 4.0
6.9 medium
EPSS
91%p100
Published
()
Modified
AI analysis

CVE-2024-11320 is a command injection flaw (CWE-77) in the LDAP authentication mechanism of the Pandora FMS monitoring platform, allowing arbitrary commands to be executed on the server. It affects Pandora FMS versions 700 through 777.4 and, per the CVSS 4.0 vector, is reachable over the network with low attack complexity, but requires the attacker to already hold high-privileged (administrator-level) access. Successful exploitation primarily compromises the integrity of the target system through arbitrary command execution, with limited confidentiality and availability impact per the scoring. Only deployments that use LDAP authentication are exposed to this specific flaw. There is no known public proof-of-concept or CISA KEV listing yet, but EPSS assigns a 91% probability of exploitation within 30 days (100th percentile), so defenders should patch promptly despite no confirmed in-the-wild exploitation.

What to do: Upgrade all Pandora FMS deployments running versions 700 through 777.4 to a release newer than 777.4 per the vendor advisory (the available data does not specify a fixed version number). Deployments that cannot patch promptly should verify whether LDAP authentication is enabled and, if so, disable or restrict it (e.g., limit administrative access to trusted sources) since only LDAP-based deployments are exploitable. Administrators should also audit privileged accounts and server logs for signs of unexpected command execution.

Affected
Pandora FMS700 through 777.4 (inclusive)
Estimated exposure
moderate≈10,000–50,000 deployments, of which only the subset using LDAP authentication is directly exploitable — Pandora FMS is a niche enterprise monitoring platform whose total active deployment base is generally estimated in the low tens of thousands, public internet scans typically index only a few thousand exposed instances, and…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Arbitrary commands execution on the server by exploiting a command injection vulnerability in the LDAP authentication mechanism. This issue affects Pandora FMS: from 700 through <=777.4

Vendors
pandorafms
Products
pandora fms
Weakness
CWE-77
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:H/VA:L/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:N/R:U/V:C/RE:M/U:Amber

In the news

No ingested article mentions this CVE yet.