Vulnerability CVE-2024-2389


Published: 2024-04-02

Description:
In Flowmon versions prior to 11.1.14 and 12.3.5, an operating system command injection vulnerability has been identified.  An unauthenticated user can gain entry to the system via the Flowmon management interface, allowing for the execution of arbitrary system commands.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
Progress Flowmon 12.3.5 Local sudo Privilege Escalation
Dave Yesland
02.06.2024

Type:

CWE-264

(Permissions, Privileges, and Access Controls)

 References:
https://www.flowmon.com
https://support.kemptechnologies.com/hc/en-us/articles/24878235038733-CVE-2024-2389-Flowmon-critical-security-vulnerability

Copyright 2024, cxsecurity.com

 

Back to Top