CVE-2024-11320: Command Injection leading to RCE via LDAP Misconfiguration
Published Nov 21, 2024
·Updated
Arbitrary commands execution on the server by exploiting a command injection vulnerability in the LDAP authentication mechanism. This issue affects Pandora FMS: from 700 through <=777.4
Affected Software
1 affected component
PandoraFMS Pandora FMS>=700<777.5
Remediation
Information
Fixed un v777.5
Event History
Nov 21, 2024
CVE Published
via MITRE·10:03 AM
Data Sourced
via MITRE·10:03 AM
RemedyDescriptionWeakness
Data Sourced
via NVD·11:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-11320?
CVE-2024-11320 is considered a critical vulnerability due to its potential for arbitrary command execution on the server.
2
How do I fix CVE-2024-11320?
To fix CVE-2024-11320, upgrade Pandora FMS to version 777.5 or later.
3
What versions of Pandora FMS are affected by CVE-2024-11320?
CVE-2024-11320 affects Pandora FMS versions from 700 to 777.4 inclusive.
4
What type of vulnerability is CVE-2024-11320?
CVE-2024-11320 is a command injection vulnerability in the LDAP authentication mechanism.
5
Can CVE-2024-11320 lead to data compromise?
Yes, CVE-2024-11320 can potentially lead to unauthorized command execution, resulting in data compromise.