← Vulnerability feed

Vulnerability record · CVE-2024-12971 · published 17 March 2025

CVE-2024-12971: Pandora FMS OS Command Injection in Affected Versions

Artica · Pandora Fms

Pandora FMS versions 700 through 777.6 contain an OS command injection flaw (CWE-77) caused by improper neutralization of special elements used in a command. An attacker with high privileges can inject and execute operating system commands, compromising the confidentiality and integrity of the application and potentially the underlying host.

8.6 CVSS 4.0 High EPSS 61% · top 0.9% CWE-77 · Command injection
8.6CVSS 4.0 base score
61%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Improper Neutralization of Special Elements used in a Command vulnerability allows OS Command Injection.This issue affects Pandora FMS from 700 to 777.6

CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:L/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:N/AU:Y/R:

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityHigh CVSS score (8.6) and very high EPSS probability indicate significant risk, though exploitation requires high privileges and no public exploit is confirmed.

What it is

Pandora FMS versions 700 through 777.6 contain an OS command injection flaw (CWE-77) caused by improper neutralization of special elements used in a command. An attacker with high privileges can inject and execute operating system commands, compromising the confidentiality and integrity of the application and potentially the underlying host.

Impact

Successful exploitation allows an authenticated attacker with high privileges to execute arbitrary OS commands on the server, leading to data theft, configuration tampering, or further compromise of the host. Availability impact is limited, but confidentiality and integrity impacts are high.

Attack surface

The vulnerability is network-reachable (AV:N) with low attack complexity and no user interaction required. It requires high privileges (PR:H), meaning an attacker must already hold an administrative or similarly privileged account on the Pandora FMS instance.

Exploitation

No public exploit code or active exploitation is documented in the record; CISA KEV does not list this CVE, but EPSS indicates a high probability of exploitation activity (0.606, 99.1st percentile).

What to do

  • Upgrade Pandora FMS to a version later than 777.6 as soon as a fixed release is available from the vendor.
  • Restrict network access to the Pandora FMS management interface to trusted administrative networks only.
  • Enforce least privilege for Pandora FMS accounts and remove unnecessary high-privilege users.
  • Monitor vendor advisories for patch availability and apply emergency change procedures if exploitation is suspected.
  • Consider application-layer filtering or WAF rules to block command injection patterns in requests to Pandora FMS endpoints.

Detection

  • Monitor Pandora FMS server logs for unexpected child processes or shell command execution spawned by the web application.
  • Alert on anomalous outbound network connections or file writes originating from the Pandora FMS service account.
  • Audit administrative account activity for unusual command or configuration changes within Pandora FMS.
  • Use endpoint detection to flag command-line interpreters (e.g., cmd.exe, /bin/sh) launched by the Pandora FMS process.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-12971 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2010-4279Pandora FMS default config allows authentication bypassPandora FMS 3.1 and earlier ships with an empty loginhash_pwd field in its default configuration, so the console accepts a crafted login request with…EPSS 66%analysed9.8CVE-2023-44091Artica pandora fms sql injection vulnerabilityImproper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Pandora FMS on all allows SQL Injection. This u…EPSS 0.45%9.8CVE-2023-4677Artica pandora fms improper authentication vulnerabilityCron log backup files contain administrator session IDs. It is trivial for any attacker who can reach the Pandora FMS Console to scrape the cron logs…EPSS 0.49%9.8CVE-2023-41790Artica pandora fms uncontrolled search path element vulnerabilityUncontrolled Search Path Element vulnerability in Pandora FMS on all allows Leveraging/Manipulating Configuration File Search Paths. This vulnerabili…EPSS 0.57%9.8CVE-2021-32098Artica pandora fms deserialization of untrusted data vulnerabilityArtica Pandora FMS 742 allows unauthenticated attackers to perform Phar deserialization.EPSS 2.5%9.8CVE-2021-32099Artica pandora fms sql injection vulnerabilityA SQL injection vulnerability in the pandora_console component of Artica Pandora FMS 742 allows an unauthenticated attacker to upgrade his unprivileg…EPSS 13%9.8CVE-2020-26518Artica pandora fms sql injection vulnerabilityArtica Pandora FMS before 743 allows unauthenticated attackers to conduct SQL injection attacks via the pandora_console/include/chart_generator.php s…EPSS 2.1%9.8CVE-2018-11221Artica pandora fms unrestricted file upload vulnerabilityUnauthenticated untrusted file upload in Artica Pandora FMS through version 7.23 allows an attacker to upload an arbitrary plugin via include/ajax/up…EPSS 5.6%

Source: NIST National Vulnerability Database (record CVE-2024-12971), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.