Maximum severity Flowmon bug has a public exploit, patch now
ID: 22ba24fd-3bed-5c23-a3e8-c77e2164eedd
STIX ID: report--22ba24fd-3bed-5c23-a3e8-c77e2164eedd
Feed Name: Bleeping Computer
Threat Score
Progress Flowmon has a critical 10/10 vulnerability (CVE-2024-2389) allowing unauthenticated remote command execution; public PoC exploit code and demonstrations exist, researchers showed webshell planting and privilege escalation, and several hundred Flowmon instances appear internet-exposed. Progress released patched versions (v12.3.5 and 11.1.14) and urged updates, while vendor advisories reported no confirmed active exploitation but multiple PoCs and warnings were published.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
