HIGH · 9.3

CVE-2009-4502

The NET_TCP_LISTEN function in net.c in Zabbix Agent before 1.6.7, when running on FreeBSD or Solaris, allows remote attackers to bypass the EnableRemoteCommands setting and execute arbitrary commands...

Vulnerability Description

The NET_TCP_LISTEN function in net.c in Zabbix Agent before 1.6.7, when running on FreeBSD or Solaris, allows remote attackers to bypass the EnableRemoteCommands setting and execute arbitrary commands via shell metacharacters in the argument to net.tcp.listen. NOTE: this attack is limited to attacks from trusted IP addresses.

CVSS Score

9.3

HIGH

AV:N/AC:M/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
ZabbixZabbix<= 1.6.6
FreebsdFreebsdAll versions
SunSolarisAll versions

Related Weaknesses (CWE)

References

FAQ

What is CVE-2009-4502?

CVE-2009-4502 is a vulnerability with a CVSS score of 9.3 (HIGH). The NET_TCP_LISTEN function in net.c in Zabbix Agent before 1.6.7, when running on FreeBSD or Solaris, allows remote attackers to bypass the EnableRemoteCommands setting and execute arbitrary commands...

How severe is CVE-2009-4502?

CVE-2009-4502 has been rated HIGH with a CVSS base score of 9.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2009-4502?

Check the references section above for vendor advisories and patch information. Affected products include: Zabbix Zabbix, Freebsd Freebsd, Sun Solaris.