CVE-2024-2389: Flowmon Unauthenticated Command Injection Vulnerability

High PUBLISHED
Vendor: Progress Software Product: Flowmon

Not yet in CISA KEV

Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Quick Answers

What is CVE-2024-2389?

CVE-2024-2389 is Flowmon Unauthenticated Command Injection Vulnerability affecting Progress Software Flowmon. In Flowmon versions prior to 11.1.14 and 12.3.5, an operating system command injection vulnerability has been identified.  An unauthenticated user can gain entry to the system via the Flowmon management interface,...

Is CVE-2024-2389 actively exploited?

Yes. KEVIntel tracks CVE-2024-2389 as a known exploited vulnerability. Confidence is high.

What exploitation activity has KEVIntel observed?

KEVIntel has not recorded sensor-observed exploitation attempts for CVE-2024-2389.

Which versions are affected?

CVE-2024-2389 affects Progress Software Flowmon. KEVIntel lists 4 version rows; examples include 11.x to < 11.1.14, 12.x to < 12.3.5, and 11.X to < 11.1.14.

How should organizations remediate it?

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Is it in CISA KEV?

No. CVE-2024-2389 is not currently listed in CISA KEV.

At a Glance

In Flowmon versions prior to 11.1.14 and 12.3.5, an operating system command injection vulnerability has been identified.  An unauthenticated user can gain entry to the system via the Flowmon management interface, allowing for the execution of arbitrary system commands.

nuclei_scanner
CVE Published
Apr 02, 2024
Exploitation Reported
Jun 06, 2026
CVSS
10.0 Critical
EPSS
93.9%
Remote Low complexity No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
progress
flowmon_os

11.x to < 11.1.14

Affected
progress
flowmon_os

12.x to < 12.3.5

Affected
Progress Software
Flowmon

11.X to < 11.1.14

Affected
Progress Software
Flowmon

12.X to < 12.3.5

Affected

CVE References