April 3, 2024, noon | MalBot

Malware Analysis, News and Indicators - Latest topics malware.news

Critical OS Command Injection Flaw in Progress Flowmon: CVE-2024-2389

Progress disclosed a highly critical vulnerability, CVE-2024-2389, that affects the Flowmon product. Exploiting this vulnerability could let attackers obtain sensitive data and network configurations, enabling additional disruptive attacks across the broader network.


Flowmon, developed by Progress, is a widely used network monitoring and security solution that gives IT teams visibility into network performance and security. Plus, users can utilize the software for effective reporting and alerting of network threats.




Flowmon’s …

attackers attacks command command injection critical critical vulnerability cve cve-2024 data exploiting flaw flowmon injection injection flaw monitoring network network monitoring os command product progress sensitive sensitive data vulnerability

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Senior Security Researcher - Linux MacOS EDR (Cortex)

@ Palo Alto Networks | Tel Aviv-Yafo, Israel

Sr. Manager, NetSec GTM Programs

@ Palo Alto Networks | Santa Clara, CA, United States

SOC Analyst I

@ Fortress Security Risk Management | Cleveland, OH, United States