Vulnerability record · CVE-2019-20224 · published 9 January 2020
CVE-2019-20224: Pandora FMS netflow_get_stats OS command injection
Artica · Pandora Fms
Pandora FMS 7.0NG passes the ip_src parameter from an index.php?operation/netflow/nf_live_view request into netflow_get_stats in functions_netflow.php without neutralizing shell metacharacters, allowing OS command injection. The flaw was fixed in Pandora FMS 7.0 NG 742, so any deployment still on the affected 7.0NG build is exposed.
Description
netflow_get_stats in functions_netflow.php in Pandora FMS 7.0NG allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ip_src parameter in an index.php?operation/netflow/nf_live_view request. This issue has been fixed in Pandora FMS 7.0 NG 742.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with public exploit code and a very high EPSS score, but exploitation requires an authenticated account, keeping it below critical.
What it is
Pandora FMS 7.0NG passes the ip_src parameter from an index.php?operation/netflow/nf_live_view request into netflow_get_stats in functions_netflow.php without neutralizing shell metacharacters, allowing OS command injection. The flaw was fixed in Pandora FMS 7.0 NG 742, so any deployment still on the affected 7.0NG build is exposed.
Impact
An attacker with a valid Pandora FMS account can run arbitrary operating system commands on the server, leading to full compromise of the monitoring host and any data or credentials it holds.
Attack surface
Reachable over the network through the netflow live view endpoint; the CVSS vector shows PR:L, so a low-privileged authenticated session is required and no user interaction is needed.
Exploitation
Not listed in CISA KEV, but EPSS is 0.4968 (98.8th percentile) and multiple references are tagged Exploit, indicating public exploit code exists and exploitation is likely.
What to do
- Upgrade Pandora FMS to 7.0 NG 742 or later, which contains the fix.
- If immediate upgrade is not possible, restrict access to the netflow live view endpoint and the Pandora FMS web interface to trusted networks.
- Review and minimize Pandora FMS accounts, removing or disabling unused low-privileged users.
- Run the Pandora FMS web service with a least-privilege OS account and limit its ability to spawn shells.
- Monitor vendor advisories for any further fixes or backports for the 7.0NG branch.
Detection
- Search web or proxy logs for requests to index.php?operation/netflow/nf_live_view containing shell metacharacters such as ;, |, $(), or backticks in the ip_src parameter.
- Alert on unexpected child processes (for example sh, bash, curl, wget, nc) spawned by the Pandora FMS web server user.
- Audit Pandora FMS application logs for anomalous netflow live view activity from accounts that do not normally use that feature.
- Baseline outbound network connections from the Pandora FMS host and flag new destinations that follow netflow live view requests.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2019-20224 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-20224), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.