CVE-2024-2389
In Flowmon versions prior to 11.1.14 and 12.3.5, an operating system command injection vulnerability has been identified. An unauthenticated user can gain entry to the system via the Flowmon management interface, allowing for the execution of arbitrary system commands.
- Affected products
- Flowmon
- Progress Flowmon
- < 11.1.14, 12.3.5
- Fix
- Available
- CVSS 3.1
- 10.0 CRITICAL
- EPSS
- 92.9% (100th percentile)
- Weakness
- CWE-78
- NVD status
- Analyzed
- Published
- 2024-04-02
- Attack patterns
- CAPEC-242
CVE-2024-2389 at NVD
8 known exploits for CVE-2024-2389
Proof-of-concept code and exploit modules indexed by Sploitus
Flowmon Unauthenticated Command Injection Exploit
Progress Flowmon 12.3.5 Local sudo Privilege Escalation Exploit
Progress Flowmon 12.3.5 Local sudo Privilege Escalation
Flowmon Unauthenticated Command Injection Exploit
Flowmon Unauthenticated Command Injection
Flowmon Unauthenticated Command Injection
Progress Flowmon Local sudo privilege escalation
CVE-2024-23897 - Jenkins <= 2.441 & <= LTS 2.426.2 PoC And Scanner