PT-2024-2667 · Flowmon · Flowmon

Published

2024-04-02

·

Updated

2025-12-16

·

CVE-2024-2389

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Flowmon versions prior to 11.1.14 and 12.3.5
Description A command injection vulnerability has been identified in Flowmon, allowing an unauthenticated user to gain entry to the system via the management interface and execute arbitrary system commands. This vulnerability can be exploited by sending specially crafted API requests. Over 1,500 companies worldwide are potentially affected, including SEGA and Volkswagen. There have been reports of proof-of-concept exploits being released, and users are urged to update to versions 12.3.4 and 11.1.14 to mitigate the risk.
Recommendations For versions prior to 11.1.14, update to version 11.1.14 or later. For versions prior to 12.3.5, update to version 12.3.5 or later. As a temporary workaround, consider restricting access to the management interface to minimize the risk of exploitation.

Exploit

Fix

RCE

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2024-02741
CVE-2024-2389

Affected Products

Flowmon