CVE-2024-12971
moderateAuthenticated OS Command Injection in Artica Pandora FMS
CVE-2024-12971 is an OS command injection flaw (CWE-77) in Artica Pandora FMS in which improperly neutralized special elements in user-supplied input allow arbitrary operating system commands to be run on the monitoring server. It is triggered through Pandora FMS functionality that passes input into OS commands, and the CVSS 4.0 vector (AV:N/AC:L/PR:H/UI:N) indicates exploitation requires network access and a high-privilege (admin-level) account, but no user interaction. A successful attacker gains command execution on the host with high confidentiality and integrity impact on the vulnerable component, typically meaning broad read/write access to monitoring data and the underlying system. Any organization running Pandora FMS versions 700 through 777.6 is affected. No public proof-of-concept or confirmed in-the-wild exploitation is known, but EPSS assigns a 60.6% probability of exploitation within 30 days (99th percentile), so attackers may target it soon.
What to do: Upgrade Pandora FMS to a current release later than 777.6, which addresses this flaw. Until patched, restrict console and admin-level access to trusted networks and audit for unauthorized or dormant administrator accounts, since high privileges are required for exploitation. Monitor vendor advisories from Artica for the exact fixed release.
| Artica Pandora FMS | 700 through 777.6 (inclusive) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper Neutralization of Special Elements used in a Command vulnerability allows OS Command Injection.This issue affects Pandora FMS from 700 to 777.6
- Vendors
- artica
- Products
- pandora fms
- Weakness
- CWE-77
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:U/V:C/RE:L/U:Green
In the news0 stories
No ingested article mentions this CVE yet.