S4E just found a high top 10 tcp port service scan
critical·Product Based Web Vulnerabilities·Updated Jul 8, 2024

CVE-2024-2389 Scanner

CVE-2024-2389 scanner - Command Injection vulnerability in Progress Kemp Flowmon

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3.2k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2024-2389
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

In Flowmon versions prior to 11.1.14 and 12.3.5, an operating system command injection vulnerability has been identified.  An unauthenticated user can gain entry to the system via the Flowmon management interface, allowing for the execution of arbitrary system commands.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Flowmonby Progress Software
AFFECTED< 11.1.14SAFE ✓≥ 11.1.14
flowmon_osby progress
AFFECTED< 11.1.14SAFE ✓≥ 11.1.14
flowmon_osby progress
AFFECTED< 12.3.5SAFE ✓≥ 12.3.5
Updated Aug 22, 2026View on NVD →
Detail

Progress Kemp Flowmon is widely used by network administrators to monitor and manage network traffic. It is deployed in various industries, including healthcare, finance, and telecommunications, to ensure network performance and security. The software offers features such as traffic analysis, anomaly detection, and application performance monitoring. It helps in identifying network bottlenecks and potential security threats. The product is crucial for maintaining optimal network performance and security compliance.

The Command Injection vulnerability in Progress Kemp Flowmon allows unauthenticated users to execute arbitrary system commands. This vulnerability is due to improper input validation in the management interface. Exploiting this flaw can lead to complete system compromise. Versions prior to 11.1.14 and 12.3.5 are affected by this issue.

The vulnerability exists in the Flowmon management interface, specifically within a URL parameter that fails to properly sanitize user input. By injecting crafted commands into this parameter, attackers can execute arbitrary system commands on the host. This can be achieved by sending a specially crafted GET request to the vulnerable endpoint. The affected parameter is not adequately validated, allowing for the execution of malicious commands, potentially compromising the entire system.

Exploitation of this vulnerability can lead to severe consequences, including unauthorized access to sensitive data, disruption of services, and full control over the affected system. Attackers can manipulate system configurations, extract confidential information, and use the compromised system as a launchpad for further attacks. The impact of such an exploitation can be catastrophic for the organization, leading to data breaches and significant operational downtime.

Join S4E to safeguard your digital assets with our comprehensive vulnerability management platform. Detect critical vulnerabilities like Command Injection in your systems before attackers do. Benefit from detailed reports, timely alerts, and expert remediation advice to enhance your security posture. Our platform uses advanced scanning techniques to ensure your network is secure from emerging threats. Sign up today to take proactive steps towards robust cybersecurity.

References:

Solution Advice
  • Upgrade to Flowmon version 11.1.14 or 12.3.5 or later.
  • Implement input validation and sanitization for all user inputs.
  • Restrict access to the Flowmon management interface to trusted IP addresses.
  • Regularly audit and monitor system logs for any suspicious activity.
  • Apply security patches and updates promptly to all software components.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2024-2389 scanner - Command Injection vulnerability in Progress Kemp Flowmon S4E