CVE-2024-35304: System command injection through Netflow function
System command injection through Netflow function due to improper input validation, allowing attackers to execute arbitrary system commands. This issue affects Pandora FMS: from 700 through <777.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35304?
CVE-2024-35304 is considered a critical vulnerability due to the potential for arbitrary system command execution.
How do I fix CVE-2024-35304?
To fix CVE-2024-35304, upgrade Pandora FMS to a version later than 777 that addresses improper input validation.
What versions of Pandora FMS are affected by CVE-2024-35304?
CVE-2024-35304 affects Pandora FMS versions from 700 to 777 inclusive.
What are the potential impacts of CVE-2024-35304?
The potential impacts of CVE-2024-35304 include unauthorized execution of system commands, leading to data breaches or system compromise.
How can I mitigate the risk of CVE-2024-35304?
Mitigating the risk of CVE-2024-35304 involves implementing strict input validation and promptly applying patches to affected systems.