← Vulnerability feed

Vulnerability record · CVE-2024-11320 · published 21 November 2024

CVE-2024-11320: Pandora FMS LDAP authentication command injection

Pandorafms · Pandora Fms

Pandora FMS versions 700 through 777.4 contain a command injection flaw in the LDAP authentication mechanism, allowing arbitrary commands to run on the server. Because the vulnerable component is the authentication path, the flaw sits in a component that is reachable before a session is fully established, making it a serious risk for exposed instances.

6.9 CVSS 4.0 Medium EPSS 91% · top 0.2% CWE-77 · Command injection
6.9CVSS 4.0 base score
91%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Arbitrary commands execution on the server by exploiting a command injection vulnerability in the LDAP authentication mechanism. This issue affects Pandora FMS: from 700 through <=777.4

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:H/VA:L/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:N/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityRemote command injection in an authentication component with a very high EPSS score warrants urgent patching despite the medium CVSS rating and privilege requirement.

What it is

Pandora FMS versions 700 through 777.4 contain a command injection flaw in the LDAP authentication mechanism, allowing arbitrary commands to run on the server. Because the vulnerable component is the authentication path, the flaw sits in a component that is reachable before a session is fully established, making it a serious risk for exposed instances.

Impact

An attacker who can influence the LDAP authentication input can execute arbitrary commands on the Pandora FMS server, gaining code execution in the context of the service. The CVSS vector rates confidentiality and availability impact as low and integrity impact as high, so full server compromise is plausible.

Attack surface

The vector is network reachable (AV:N) with low attack complexity, but requires high privileges (PR:H) and some user interaction (UI:P). It is reached through the LDAP authentication mechanism, so the attacker needs a position or credentials that let them supply the malicious authentication input.

Exploitation

No CISA KEV listing and no ransomware association are recorded, but EPSS is very high at 0.91046 (99.8th percentile), indicating strong predicted exploitation activity. The only reference is a vendor advisory, so no public exploit details are confirmed in this record.

What to do

  • Upgrade Pandora FMS past 777.4 to a fixed release per the vendor advisory.
  • If patching is delayed, disable or restrict LDAP authentication and fall back to local accounts.
  • Limit network exposure of the Pandora FMS web interface to trusted management networks.
  • Audit and rotate LDAP bind credentials and review accounts with high privileges.
  • Monitor the server for unexpected child processes spawned by the web service.

Detection

  • Review web and application logs for LDAP authentication requests containing shell metacharacters or unusual characters.
  • Monitor for unexpected process creation by the Pandora FMS web server user, especially shell interpreters.
  • Alert on outbound connections from the Pandora FMS server to unfamiliar hosts after authentication events.
  • Correlate LDAP authentication failures with subsequent command execution or file changes on the host.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-11320 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-2807Pandorafms pandora fms authentication bypass by spoofing vulnerabilityAuthentication Bypass by Spoofing vulnerability in the password reset process of Pandora FMS allows an unauthenticated attacker to initiate a passwor…EPSS 0.62%9.8CVE-2022-43979Pandorafms pandora fms unrestricted file upload vulnerabilityThere is a Path Traversal that leads to a Local File Inclusion in Pandora FMS v764. A function is called to check that the parameter that the user ha…EPSS 0.82%9.8CVE-2021-34074Pandorafms pandora fms unrestricted file upload vulnerabilityPandoraFMS <=7.54 allows arbitrary file upload, it leading to remote command execution via the File Manager. To bypass the built-in protection, a rel…EPSS 7.5%9.8CVE-2020-13854Pandorafms pandora fms improper privilege management vulnerabilityArtica Pandora FMS 7.44 allows privilege escalation.EPSS 3.0%9.0CVE-2020-11749Pandorafms pandora fms cross-site scripting vulnerabilityPandora FMS 7.0 NG <= 746 suffers from Multiple XSS vulnerabilities in different browser views. A network administrator scanning a SNMP device can tr…EPSS 16%8.8CVE-2023-44088Pandorafms pandora fms sql injection vulnerabilityImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pandora FMS on all allows SQL Injection. Arbitr…EPSS 0.73%8.8CVE-2022-26309Pandorafms pandora fms cross-site request forgery vulnerabilityPandora FMS v7.0NG.759 allows Cross-Site Request Forgery in Bulk operation (User operation) resulting in elevation of privilege to Administrator grou…EPSS 0.28%8.8CVE-2022-26310Pandorafms pandora fms improper authorization vulnerabilityPandora FMS v7.0NG.760 and below allows an improper authorization in User Management where any authenticated user with access to the User Management …EPSS 0.69%

Source: NIST National Vulnerability Database (record CVE-2024-11320), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.