Vulnerability record · CVE-2024-11320 · published 21 November 2024
CVE-2024-11320: Pandora FMS LDAP authentication command injection
Pandorafms · Pandora Fms
Pandora FMS versions 700 through 777.4 contain a command injection flaw in the LDAP authentication mechanism, allowing arbitrary commands to run on the server. Because the vulnerable component is the authentication path, the flaw sits in a component that is reachable before a session is fully established, making it a serious risk for exposed instances.
Description
Arbitrary commands execution on the server by exploiting a command injection vulnerability in the LDAP authentication mechanism. This issue affects Pandora FMS: from 700 through <=777.4
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:L/VI:H/VA:L/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:P/AU:N/R:
Automated analysis
high priorityRemote command injection in an authentication component with a very high EPSS score warrants urgent patching despite the medium CVSS rating and privilege requirement.
What it is
Pandora FMS versions 700 through 777.4 contain a command injection flaw in the LDAP authentication mechanism, allowing arbitrary commands to run on the server. Because the vulnerable component is the authentication path, the flaw sits in a component that is reachable before a session is fully established, making it a serious risk for exposed instances.
Impact
An attacker who can influence the LDAP authentication input can execute arbitrary commands on the Pandora FMS server, gaining code execution in the context of the service. The CVSS vector rates confidentiality and availability impact as low and integrity impact as high, so full server compromise is plausible.
Attack surface
The vector is network reachable (AV:N) with low attack complexity, but requires high privileges (PR:H) and some user interaction (UI:P). It is reached through the LDAP authentication mechanism, so the attacker needs a position or credentials that let them supply the malicious authentication input.
Exploitation
No CISA KEV listing and no ransomware association are recorded, but EPSS is very high at 0.91046 (99.8th percentile), indicating strong predicted exploitation activity. The only reference is a vendor advisory, so no public exploit details are confirmed in this record.
What to do
- Upgrade Pandora FMS past 777.4 to a fixed release per the vendor advisory.
- If patching is delayed, disable or restrict LDAP authentication and fall back to local accounts.
- Limit network exposure of the Pandora FMS web interface to trusted management networks.
- Audit and rotate LDAP bind credentials and review accounts with high privileges.
- Monitor the server for unexpected child processes spawned by the web service.
Detection
- Review web and application logs for LDAP authentication requests containing shell metacharacters or unusual characters.
- Monitor for unexpected process creation by the Pandora FMS web server user, especially shell interpreters.
- Alert on outbound connections from the Pandora FMS server to unfamiliar hosts after authentication events.
- Correlate LDAP authentication failures with subsequent command execution or file changes on the host.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://pandorafms.com/en/security/common-vulnerabilities-and-exposures/ | Vendor Advisory |
Track CVE-2024-11320 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-11320), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.