CVE-2024-11320 MEDIUM

CVE-2024-11320: Command Injection leading to RCE via LDAP Misconfiguration

Vendor Pandora Fms
Product Pandora FMS
Weakness CWE-77
Published November 21, 2024
Last update November 21, 2024

CVSS base score

6.9/10
Attack vector Network
Attack complexity Low
Privileges required High
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:H/VA:L/SC:L/SI:L/SA:N/S:P/AU:N/R:U/V:C/RE:M/U:Amber

What the vulnerability does

01Description

Arbitrary commands execution on the server by exploiting a command injection vulnerability in the LDAP authentication mechanism. This issue affects Pandora FMS: from 700 through <=777.4

Key dates

02Disclosure timeline

November 21, 2024 CVE published
November 21, 2024 Record updated