CVE-2024-2389

In Flowmon versions prior to 11.1.14 and 12.3.5, an operating system command injection vulnerability has been identified.  An unauthenticated user can gain entry to the system via the Flowmon management interface, allowing for the execution of arbitrary system commands.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:progress:flowmon:*:*:*:*:*:*:*:*
cpe:2.3:a:progress:flowmon:*:*:*:*:*:*:*:*

History

07 Feb 2025, 17:00

Type Values Removed Values Added
First Time Progress flowmon
Progress
References () https://support.kemptechnologies.com/hc/en-us/articles/24878235038733-CVE-2024-2389-Flowmon-critical-security-vulnerability - () https://support.kemptechnologies.com/hc/en-us/articles/24878235038733-CVE-2024-2389-Flowmon-critical-security-vulnerability - Vendor Advisory
References () https://www.flowmon.com - () https://www.flowmon.com - Product
CPE cpe:2.3:a:progress:flowmon:*:*:*:*:*:*:*:*

Information

Published : 2024-04-02 13:15

Updated : 2025-02-07 17:00


NVD link : CVE-2024-2389

Mitre link : CVE-2024-2389

CVE.ORG link : CVE-2024-2389


JSON object : View

Products Affected

progress

  • flowmon
CWE
CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')