CVE-2019-20224 is a critical remote command injection vulnerability affecting Pandora FMS 7.0NG, specifically within the netflow_get_stats function. An authenticated attacker can exploit this flaw by injecting shell metacharacters into the ip_src parameter, leading to arbitrary OS command execution. Rated with a CVSS score of 8.8 (High), this vulnerability is easily exploitable over the network with low privileges and no user interaction, allowing for complete compromise of confidentiality, integrity, and availability. Its EPSS score of 0.936470000 and FAUCET Risk Score of 99/100 indicate a high likelihood of exploitation. While not listed in CISA's KEV catalog or having public Metasploit exploits, Nuclei templates exist for detecting this vulnerability. Despite its high severity, there is no evidence of active exploitation, significant community discussion, or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.0_ngCPE matchmatch criteria | cpe:2.3:a:artica:pandora_fms:7.0_ng:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.