CVE-2024-35307: Argument Injection Leading to Remote Code Execution in Realtime Graph Extension
Published Jun 10, 2024
·Updated
Argument Injection Leading to Remote Code Execution in Realtime Graph Extension, allowing unauthenticated attackers to execute arbitrary code on the server. This issue affects Pandora FMS: from 700 through <777.
Affected Software
2 affected components
Pandora FMS Pandora FMS>=700<777
Artica Pandora FMS>=700<777
Remediation
Information
Fixed v777
Event History
Jun 10, 2024
CVE Published
via MITRE·02:33 PM
Data Sourced
via MITRE·02:33 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·03:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2024-35307?
CVE-2024-35307 has a high severity rating due to its potential to allow unauthenticated attackers to execute arbitrary code on the server.
2
How do I fix CVE-2024-35307?
To fix CVE-2024-35307, update your version of Pandora FMS to a version higher than 777.
3
What versions of Pandora FMS are affected by CVE-2024-35307?
CVE-2024-35307 affects Pandora FMS versions from 700 to 777.
4
Can CVE-2024-35307 be exploited remotely?
Yes, CVE-2024-35307 can be exploited remotely, allowing attackers to execute arbitrary code without authentication.
5
What type of vulnerability is CVE-2024-35307?
CVE-2024-35307 is classified as an Argument Injection vulnerability leading to Remote Code Execution.