CVE-2024-2389: Flowmon Unauthenticated Command Injection Vulnerability
In Flowmon versions prior to 11.1.14 and 12.3.5, an operating system command injection vulnerability has been identified. An unauthenticated user can gain entry to the system via the Flowmon management interface, allowing for the execution of arbitrary system commands.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-2389?
CVE-2024-2389 is classified as a critical vulnerability due to the potential for unauthenticated users to execute arbitrary system commands.
Which versions of Flowmon are affected by CVE-2024-2389?
CVE-2024-2389 affects Flowmon versions prior to 11.1.14 and 12.3.5.
How do I fix CVE-2024-2389?
To fix CVE-2024-2389, upgrade Flowmon to the latest versions 11.1.14 or 12.3.5 or above.
Can CVE-2024-2389 be exploited remotely?
Yes, CVE-2024-2389 can be exploited remotely since it allows unauthorized access through the Flowmon management interface.
What type of vulnerability is CVE-2024-2389?
CVE-2024-2389 is an operating system command injection vulnerability.