S4E just found a high top 10 tcp port service scan
high·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2019-20224 Scanner

CVE-2019-20224 scanner - OS Command Injection vulnerability in Pandora FMS 7.0NG

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2019-20224
8.8
CVSS

netflow_get_stats in functions_netflow.php in Pandora FMS 7.0NG allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ip_src parameter in an index.php?operation/netflow/nf_live_view request. This issue has been fixed in Pandora FMS 7.0 NG 742.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 21, 2026View on NVD →
Detail

Pandora FMS 7.0NG is an open source monitoring software designed for network monitoring, server monitoring, and infrastructure management. It is used by IT teams to keep track of the performance and availability of various network devices, servers, applications, databases, and other IT assets. The software is equipped with a range of features such as data visualization, alerting, reporting, and automation, which enable IT teams to proactively manage their IT infrastructure.

The CVE-2019-20224 vulnerability detected in Pandora FMS 7.0NG is a critical security flaw that can be exploited by remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ip_src parameter in an index.php?operation/netflow/nf_live_view request. This flaw can be dangerous as it provides unauthorized access to the system, which can lead to a range of security threats such as data theft, system hijacking, and malware infections.

When exploited, this vulnerability can lead to serious consequences as attackers can gain unauthorized access to the system and execute arbitrary OS commands. This can result in data compromise, system penetration, and other security breaches. Attackers can also use this vulnerability to inject malware into the system, steal sensitive information, or take control of the system.

Thanks to the pro features of the s4e.io platform, those who read this article can easily and quickly learn about vulnerabilities in their digital assets. With features such as asset discovery, vulnerability management, compliance reporting, and threat analysis, the platform provides comprehensive and real-time insights into security threats and risks. So, sign up today and stay one step ahead of cyber threats!

 

REFERENCES

Solution Advice

To protect against this vulnerability, organizations can take the following precautions:

  • Update to the latest version of Pandora FMS 7.0NG (742).
  • Restrict access to the software and the underlying system.
  • Implement strong access controls, such as two-factor authentication.
  • Monitor network traffic for any suspicious activity.
  • Regularly review and update security policies and procedures.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.