ZeroHour

CVE-2024-12971

moderate

Authenticated OS Command Injection in Artica Pandora FMS

CVSS 4.0
8.6 high
EPSS
61%p99
Published
()
Modified
AI analysis

CVE-2024-12971 is an OS command injection flaw (CWE-77) in Artica Pandora FMS in which improperly neutralized special elements in user-supplied input allow arbitrary operating system commands to be run on the monitoring server. It is triggered through Pandora FMS functionality that passes input into OS commands, and the CVSS 4.0 vector (AV:N/AC:L/PR:H/UI:N) indicates exploitation requires network access and a high-privilege (admin-level) account, but no user interaction. A successful attacker gains command execution on the host with high confidentiality and integrity impact on the vulnerable component, typically meaning broad read/write access to monitoring data and the underlying system. Any organization running Pandora FMS versions 700 through 777.6 is affected. No public proof-of-concept or confirmed in-the-wild exploitation is known, but EPSS assigns a 60.6% probability of exploitation within 30 days (99th percentile), so attackers may target it soon.

What to do: Upgrade Pandora FMS to a current release later than 777.6, which addresses this flaw. Until patched, restrict console and admin-level access to trusted networks and audit for unauthorized or dormant administrator accounts, since high privileges are required for exploitation. Monitor vendor advisories from Artica for the exact fixed release.

Affected
Artica Pandora FMS700 through 777.6 (inclusive)
Estimated exposure
moderate≈1k–10k internet-exposed Pandora FMS consoles (total deployments likely higher, many internal) — Pandora FMS is an open-source enterprise monitoring platform whose consoles occasionally appear in public internet scans in the low thousands, while most enterprise deployments sit on internal networks, so externally exposed instances…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper Neutralization of Special Elements used in a Command vulnerability allows OS Command Injection.This issue affects Pandora FMS from 700 to 777.6

Vendors
artica
Products
pandora fms
Weakness
CWE-77
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:U/V:C/RE:L/U:Green

In the news

No ingested article mentions this CVE yet.