CVE-2024-2389

In Flowmon versions prior to 11.1.14 and 12.3.5, an operating system command injection vulnerability has been identified.  An unauthenticated user can gain entry to the system via the Flowmon management interface, allowing for the execution of arbitrary system commands.
Configurations

No configuration.

History

21 Nov 2024, 09:09

Type Values Removed Values Added
Summary
  • (es) En las versiones de Flowmon anteriores a la 11.1.14 y 12.3.5, se identificó una vulnerabilidad de inyección de comandos del sistema operativo. Un usuario no autenticado puede acceder al sistema a través de la interfaz de administración de Flowmon, lo que permite la ejecución de comandos arbitrarios del sistema.
References () https://support.kemptechnologies.com/hc/en-us/articles/24878235038733-CVE-2024-2389-Flowmon-critical-security-vulnerability - () https://support.kemptechnologies.com/hc/en-us/articles/24878235038733-CVE-2024-2389-Flowmon-critical-security-vulnerability -
References () https://www.flowmon.com - () https://www.flowmon.com -

02 Apr 2024, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-02 13:15

Updated : 2024-11-21 09:09


NVD link : CVE-2024-2389

Mitre link : CVE-2024-2389

CVE.ORG link : CVE-2024-2389


JSON object : View

Products Affected

No product.

CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')