CVE-2024-2389

In Flowmon versions prior to 11.1.14 and 12.3.5, an operating system command injection vulnerability has been identified.  An unauthenticated user can gain entry to the system via the Flowmon management interface, allowing for the execution of arbitrary system commands.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:progress:flowmon:*:*:*:*:*:*:*:*
cpe:2.3:a:progress:flowmon:*:*:*:*:*:*:*:*

History

07 Feb 2025, 17:00

Type Values Removed Values Added
CPE cpe:2.3:a:progress:flowmon:*:*:*:*:*:*:*:*
CWE CWE-78
First Time Progress
Progress flowmon
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
References () https://support.kemptechnologies.com/hc/en-us/articles/24878235038733-CVE-2024-2389-Flowmon-critical-security-vulnerability - () https://support.kemptechnologies.com/hc/en-us/articles/24878235038733-CVE-2024-2389-Flowmon-critical-security-vulnerability - Vendor Advisory
References () https://www.flowmon.com - () https://www.flowmon.com - Product

02 Apr 2024, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-04-02 13:15

Updated : 2025-02-07 17:00


NVD link : CVE-2024-2389

Mitre link : CVE-2024-2389


JSON object : View

Products Affected

progress

  • flowmon
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')