Lucene search

K
cvelistMitreCVELIST:CVE-2009-4502
HistoryDec 31, 2009 - 6:00 p.m.

CVE-2009-4502

2009-12-3118:00:00
mitre
www.cve.org
5
zabbix agent
net_tcp_listen
vulnerability
freebsd
solaris
remote attackers
bypass
enableremotecommands
arbitrary commands
shell metacharacters
trusted ip addresses

AI Score

7.6

Confidence

Low

EPSS

0.652

Percentile

97.9%

The NET_TCP_LISTEN function in net.c in Zabbix Agent before 1.6.7, when running on FreeBSD or Solaris, allows remote attackers to bypass the EnableRemoteCommands setting and execute arbitrary commands via shell metacharacters in the argument to net.tcp.listen. NOTE: this attack is limited to attacks from trusted IP addresses.

AI Score

7.6

Confidence

Low

EPSS

0.652

Percentile

97.9%