Vulnerability record · CVE-2024-12971 · published 17 March 2025
CVE-2024-12971: Pandora FMS OS Command Injection in Affected Versions
Artica · Pandora Fms
Pandora FMS versions 700 through 777.6 contain an OS command injection flaw (CWE-77) caused by improper neutralization of special elements used in a command. An attacker with high privileges can inject and execute operating system commands, compromising the confidentiality and integrity of the application and potentially the underlying host.
Description
Improper Neutralization of Special Elements used in a Command vulnerability allows OS Command Injection.This issue affects Pandora FMS from 700 to 777.6
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:
Automated analysis
high priorityHigh CVSS score (8.6) and very high EPSS probability indicate significant risk, though exploitation requires high privileges and no public exploit is confirmed.
What it is
Pandora FMS versions 700 through 777.6 contain an OS command injection flaw (CWE-77) caused by improper neutralization of special elements used in a command. An attacker with high privileges can inject and execute operating system commands, compromising the confidentiality and integrity of the application and potentially the underlying host.
Impact
Successful exploitation allows an authenticated attacker with high privileges to execute arbitrary OS commands on the server, leading to data theft, configuration tampering, or further compromise of the host. Availability impact is limited, but confidentiality and integrity impacts are high.
Attack surface
The vulnerability is network-reachable (AV:N) with low attack complexity and no user interaction required. It requires high privileges (PR:H), meaning an attacker must already hold an administrative or similarly privileged account on the Pandora FMS instance.
Exploitation
No public exploit code or active exploitation is documented in the record; CISA KEV does not list this CVE, but EPSS indicates a high probability of exploitation activity (0.606, 99.1st percentile).
What to do
- Upgrade Pandora FMS to a version later than 777.6 as soon as a fixed release is available from the vendor.
- Restrict network access to the Pandora FMS management interface to trusted administrative networks only.
- Enforce least privilege for Pandora FMS accounts and remove unnecessary high-privilege users.
- Monitor vendor advisories for patch availability and apply emergency change procedures if exploitation is suspected.
- Consider application-layer filtering or WAF rules to block command injection patterns in requests to Pandora FMS endpoints.
Detection
- Monitor Pandora FMS server logs for unexpected child processes or shell command execution spawned by the web application.
- Alert on anomalous outbound network connections or file writes originating from the Pandora FMS service account.
- Audit administrative account activity for unusual command or configuration changes within Pandora FMS.
- Use endpoint detection to flag command-line interpreters (e.g., cmd.exe, /bin/sh) launched by the Pandora FMS process.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://pandorafms.com/en/security/common-vulnerabilities-and-exposures/ | Vendor Advisory |
Track CVE-2024-12971 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-12971), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.