CVE Feed

    Dashboard / CVE / CVE-2024-2389

    CVE-2024-2389

    In Flowmon versions prior to 11.1.14 and 12.3.5, an operating system command injection vulnerability has been identified.  An unauthenticated user can gain entry to the system via the Flowmon management interface, allowing for the execution of arbitrary system commands.

    Published:Apr 2, 2024
    Last Modified:Dec 16, 2025
    EPS:Apr 2, 2024
    EPSS Score:0.94314
    CVSS Score:10

    Affected Products

    Vendor
    Progress
    Product
    Flowmon
    Vendor
    Progress
    Product
    Flowmon Os

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High