Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

U32I@Proton.Me

#13650of 53,632
19.6Total CVSS
Vulnerabilities · 2
Critical
2
PT-2024-26424
9.8
2024-06-10
Unknown · Pandora Fms · CVE-2024-35304
**Name of the Vulnerable Software and Affected Versions** Pandora FMS versions 700 through 776 **Description** The issue is related to system command injection through the Netflow function due to improper input validation, allowing attackers to execute arbitrary system commands. **Recommendations** For Pandora FMS versions 700 through 776, update to a version that includes proper input validation for the Netflow function to prevent system command injection. As a temporary workaround, consider restricting access to the Netflow function until a patch is available.
PT-2024-26425
9.8
2024-06-10
Unknown · Pandora Fms · CVE-2024-35307
**Name of the Vulnerable Software and Affected Versions** Pandora FMS versions 700 through 776 **Description** The issue allows unauthenticated attackers to execute arbitrary code on the server through Argument Injection Leading to Remote Code Execution in the Realtime Graph Extension. **Recommendations** For Pandora FMS versions 700 through 776, update to a version that is not affected by this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.