← Vulnerability feed

Vulnerability record · CVE-2019-20224 · published 9 January 2020

CVE-2019-20224: Pandora FMS netflow_get_stats OS command injection

Artica · Pandora Fms

Pandora FMS 7.0NG passes the ip_src parameter from an index.php?operation/netflow/nf_live_view request into netflow_get_stats in functions_netflow.php without neutralizing shell metacharacters, allowing OS command injection. The flaw was fixed in Pandora FMS 7.0 NG 742, so any deployment still on the affected 7.0NG build is exposed.

8.8 CVSS 3.1 High EPSS 50% · top 1.1% CWE-78 · OS command injection
8.8CVSS 3.1 base score, v2 9.0
50%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References, 8 tagged exploit
17 Jun 2026Last modified by NVD

Description

netflow_get_stats in functions_netflow.php in Pandora FMS 7.0NG allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ip_src parameter in an index.php?operation/netflow/nf_live_view request. This issue has been fixed in Pandora FMS 7.0 NG 742.

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: high.

high priorityCVSS 8.8 with public exploit code and a very high EPSS score, but exploitation requires an authenticated account, keeping it below critical.

What it is

Pandora FMS 7.0NG passes the ip_src parameter from an index.php?operation/netflow/nf_live_view request into netflow_get_stats in functions_netflow.php without neutralizing shell metacharacters, allowing OS command injection. The flaw was fixed in Pandora FMS 7.0 NG 742, so any deployment still on the affected 7.0NG build is exposed.

Impact

An attacker with a valid Pandora FMS account can run arbitrary operating system commands on the server, leading to full compromise of the monitoring host and any data or credentials it holds.

Attack surface

Reachable over the network through the netflow live view endpoint; the CVSS vector shows PR:L, so a low-privileged authenticated session is required and no user interaction is needed.

Exploitation

Not listed in CISA KEV, but EPSS is 0.4968 (98.8th percentile) and multiple references are tagged Exploit, indicating public exploit code exists and exploitation is likely.

What to do

  • Upgrade Pandora FMS to 7.0 NG 742 or later, which contains the fix.
  • If immediate upgrade is not possible, restrict access to the netflow live view endpoint and the Pandora FMS web interface to trusted networks.
  • Review and minimize Pandora FMS accounts, removing or disabling unused low-privileged users.
  • Run the Pandora FMS web service with a least-privilege OS account and limit its ability to spawn shells.
  • Monitor vendor advisories for any further fixes or backports for the 7.0NG branch.

Detection

  • Search web or proxy logs for requests to index.php?operation/netflow/nf_live_view containing shell metacharacters such as ;, |, $(), or backticks in the ip_src parameter.
  • Alert on unexpected child processes (for example sh, bash, curl, wget, nc) spawned by the Pandora FMS web server user.
  • Audit Pandora FMS application logs for anomalous netflow live view activity from accounts that do not normally use that feature.
  • Baseline outbound network connections from the Pandora FMS host and flag new destinations that follow netflow live view requests.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-20224 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2010-4279Pandora FMS default config allows authentication bypassPandora FMS 3.1 and earlier ships with an empty loginhash_pwd field in its default configuration, so the console accepts a crafted login request with…EPSS 66%analysed9.8CVE-2023-44091Artica pandora fms sql injection vulnerabilityImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pandora FMS on all allows SQL Injection. This u…EPSS 0.45%9.8CVE-2023-4677Artica pandora fms improper authentication vulnerabilityCron log backup files contain administrator session IDs. It is trivial for any attacker who can reach the Pandora FMS Console to scrape the cron logs…EPSS 0.49%9.8CVE-2023-41790Artica pandora fms uncontrolled search path element vulnerabilityUncontrolled Search Path Element vulnerability in Pandora FMS on all allows Leveraging/Manipulating Configuration File Search Paths. This vulnerabili…EPSS 0.57%9.8CVE-2021-32098Artica pandora fms deserialization of untrusted data vulnerabilityArtica Pandora FMS 742 allows unauthenticated attackers to perform Phar deserialization.EPSS 2.5%9.8CVE-2021-32099Artica pandora fms sql injection vulnerabilityA SQL injection vulnerability in the pandora_console component of Artica Pandora FMS 742 allows an unauthenticated attacker to upgrade his unprivileg…EPSS 13%9.8CVE-2020-26518Artica pandora fms sql injection vulnerabilityArtica Pandora FMS before 743 allows unauthenticated attackers to conduct SQL injection attacks via the pandora_console/include/chart_generator.php s…EPSS 2.1%9.8CVE-2018-11221Artica pandora fms unrestricted file upload vulnerabilityUnauthenticated untrusted file upload in Artica Pandora FMS through version 7.23 allows an attacker to upload an arbitrary plugin via include/ajax/up…EPSS 5.6%

Source: NIST National Vulnerability Database (record CVE-2019-20224), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.