CVE-2024-12992: Remote Code Execution leads to Command Injection
Published Mar 17, 2025
·Updated
Improper Neutralization of Special Elements used in a Command vulnerability allows OS Command Injection via RCE.
This issue affects Pandora FMS from 700 to 777.6
.
Affected Software
2 affected components
Pandora FMS Pandora FMS>=700<=777.6
Artica Pandora FMS>=700<777.8
Remediation
Information
Fixed in v781 and v777.8
Event History
Mar 17, 2025
CVE Published
via MITRE·09:21 AM
Data Sourced
via MITRE·09:21 AM
RemedyDescriptionWeakness
Data Sourced
via NVD·10:15 AM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-12992?
CVE-2024-12992 is considered a high severity vulnerability that allows OS Command Injection.
2
How do I fix CVE-2024-12992?
To fix CVE-2024-12992, update Pandora FMS to version 777.7 or later.
3
What versions of Pandora FMS are affected by CVE-2024-12992?
CVE-2024-12992 affects Pandora FMS versions from 700 to 777.6.
4
What type of vulnerability is CVE-2024-12992?
CVE-2024-12992 is an improper neutralization vulnerability that allows for command injection.
5
How can CVE-2024-12992 impact my system?
CVE-2024-12992 can lead to remote code execution, potentially allowing attackers to execute arbitrary commands on the affected system.