CVE-2019-11043: PHP FastCGI Process Manager (FPM)
EPSS99.7%No. 158 of 1739 in KEV
CVE year2019~3 yrs before listing
Same vendor in KEV3
Same product1
| Field | Value |
|---|---|
| Vendor | PHP |
| Product | FastCGI Process Manager (FPM) |
| Name | PHP FastCGI Process Manager (FPM) Buffer Overflow Vulnerability |
| Added to KEV | 2022-03-25 |
| US federal due date | 2022-04-15 |
| Ransomware use | Known |
| CWE | CWE-120 |
CISA description
In some versions of PHP in certain configurations of FPM setup, it is possible to cause FPM module to write past allocated buffers allowing the possibility of remote code execution.
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page
A PHP FastCGI Process Manager (FPM) vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2022-03-25.