Pandora FMS OS Command Injection Vulnerability

Vulnerability

A command injection vulnerability allowing operating system command execution has been identified in Pandora FMS versions 700 through 777.6. This vulnerability arises from improper handling of special elements in commands, which could be exploited to inject and execute arbitrary commands on the server.

Impact

Exploitation of this vulnerability allows for arbitrary command execution on the server where Pandora FMS is running.

Remediation

Users can upgrade to Pandora FMS versions 777.8 or 781 to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
3.1
impact
10.0
exploitability
4.8
remediation
7.7
relevance
0.0
threat
1.7
urgency
1.4
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.