CVE-2024-12971: QuickShell Authenticated Command Injection
Published Mar 17, 2025
·Updated
Improper Neutralization of Special Elements used in a Command vulnerability allows OS Command Injection.This issue affects Pandora FMS from 700 to 777.6
Affected Software
2 affected components
Pandora FMS Pandora FMS>=700<=777.6
Artica Pandora FMS>=700<777.8
Remediation
Information
Fixed in v781 and v777.8
Event History
Mar 17, 2025
CVE Published
via MITRE·09:19 AM
Data Sourced
via MITRE·09:19 AM
RemedyDescriptionWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-12971?
CVE-2024-12971 is categorized as a high severity vulnerability due to its potential for OS command injection.
2
How do I fix CVE-2024-12971?
To fix CVE-2024-12971, upgrade Pandora FMS to version 778 or later to address the command injection vulnerability.
3
What impact does CVE-2024-12971 have on systems?
CVE-2024-12971 allows an attacker to execute arbitrary commands on the host system, posing a significant security risk.
4
Which versions of Pandora FMS are affected by CVE-2024-12971?
CVE-2024-12971 affects Pandora FMS versions from 700 to 777.6.
5
Is there a known exploit for CVE-2024-12971?
While specific exploits for CVE-2024-12971 may not be publicly disclosed, the nature of command injection vulnerabilities means they are highly exploitable.