← All CVEs

CVE-2009-4502

high · 9.3

The NET_TCP_LISTEN function in net.c in Zabbix Agent before 1.6.7, when running on FreeBSD or Solaris, allows remote attackers to bypass the EnableRemoteCommands setting and execute arbitrary commands via shell metacharacters in the argument to net.tcp.listen. NOTE: this attack is limited to attacks from trusted IP addresses.

9.3
CVSS
21.6%
EPSS (exploit prob.)
98th
EPSS percentile
2009-12-31
Published

AV:N/AC:M/Au:N/C:C/I:C/A:C

Weaknesses

CWE-264

Affected products

VendorProductAffected versions
zabbixzabbix<= 1.6.6
zabbixzabbix1.1.2
zabbixzabbix1.1.3
zabbixzabbix1.1.4
zabbixzabbix1.1.5
zabbixzabbix1.4.2
zabbixzabbix1.4.3
zabbixzabbix1.4.4
zabbixzabbix1.4.6
freebsdfreebsdall versions
sunsolarisall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2009-4502