A Proof-of-Concept has been released for a top-severity security flaw in Progress Flowmon, a tool for monitoring network performance and visibility.
See also: Over 92,000 D-Link NAS devices have a backdoor

Progress Flowmon combines performance monitoring, diagnostics, and network detection and response functions. It is used by more than 1,500 companies worldwide, including SEGA, KIA, TDK, Volkswagen, Orange , and Tietoevry.
The security issue has a maximum severity rating of 10/10 and was discovered by researchers at Rhino Security Labs. It is currently tracked as CVE-2024-2389.
An attacker can exploit the flaw and can use a specially crafted API request to gain remote, unauthenticated access to the Flowmon web interface and execute arbitrary system commands.
Flowon developer Progress Software first reported the flaw on April 4, warning that it affects versions of the product v12.x and v11.x.The company urged system administrators to upgrade to the latest versions, 12.3.5 and 11.1.14.
The security update for the bug was released to all Flowmon customers either automatically via the “ Automatic Package Download ” system or manually from the vendor’s download center. Progress also recommended that all Flowmon operating systems be upgraded thereafter.
See also: Vulnerability in glibc allows root access on Linux distributions

Exploit code available
In a report, Rhino Security Labs published technical details about the flaw in Flowmon along with a demonstration showing how an attacker could exploit the issue to create a webshell and escalate root.
The researchers explain that they were able to inject commands by manipulating the “pluginPath” or “file parameters” to embed malicious commands. By using command substitution syntax, e.g. $(…), the researchers could achieve arbitrary command execution.
"The command is executed blindly, so it is not possible to see the output of the executed command, but it is possible to write a webshell to /var/www/shtml/," the researchers explain.
It is worth noting that in a warning about two weeks ago, the Italian CSIRT stated that an exploit.
See also: Hackers exploit Magento vulnerability and insert backdoor into sites
A Proof-of-Concept Exploit, such as the one released for the Flowmon bug, refers to a program that demonstrates how a specific bug or vulnerability in a system or software. Its purpose is to prove that the vulnerability exists and can be exploited. This type of exploit is not designed to cause damage, but to demonstrate the possibility of exploitation. It is often used by security researchers to highlight vulnerabilities to organizations and software companies so that they can fix them. However, it is important to note that Proof-of-Concept Exploits can also be abused by malicious users. If someone has access to such an exploit and knows how to use it, they can exploit the vulnerability for malicious purposes.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: bleepingcomputer
