Command Injection in Netflow path
41Vexday Risk Score
Patch soon. It has a working public exploit.
ssvc Attendcvss 7epss 23%
from disclosure to weapon0 days
Published on NVDJun 27
metasploitJun 27
exploitation probability
23%top 2% of all CVEs
observed exploitation
nono source reports it
Improper Neutralization of Special Elements in the Netflow directory field may allow OS command injection. This issue affects Pandora FMS 774 through 778
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:H/VA:L/SC:L/SI:L/SA:L/S:N/AU:N/R:U/V:D/RE:M/U:Green
Affected products
Pandora FMS · Pandora FMS