Record summary

CVE-2024-12971 has a selected CVSS score of 8.6 (high); EIP currently links 1 catalogued exploit.

Description

Improper Neutralization of Special Elements used in a Command vulnerability allows OS Command Injection.This issue affects Pandora FMS from 700 to 777.6

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1

CISA SSVC decision

ExploitationNone
AutomatableNo
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Mar 17, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: unaffected

CVE List700 to ≤ 777.6affected

Proofs of concept

1

Catalogued exploits

MetasploitPandora FMS authenticated command injection leading to RCE via chromium_path or phantomjs_binMetasploit exploitby h00die-gr3y <h00die.gr3y@gmail.com>Not analyzed1 file

Ruby

Metasploit

PoC details

References

2