peter bassill · operator
$ cve CVE-2009-4502 JSON

CVE-2009-4502 EXPLOIT

9.3
HIGH · CVSS 2.0 · EPSS 21.6% (pctl 98)

Patch early

A public exploit exists.

Description

The NET_TCP_LISTEN function in net.c in Zabbix Agent before 1.6.7, when running on FreeBSD or Solaris, allows remote attackers to bypass the EnableRemoteCommands setting and execute arbitrary commands via shell metacharacters in the argument to net.tcp.listen. NOTE: this attack is limited to attacks from trusted IP addresses.

Scoring

CVSS9.3 (HIGH, v2.0)
VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS21.57% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-264
On CISA KEVno
Public exploityes
Published2009-12-31
Last modified2026-06-16

Affected (3)

VendorProduct
freebsdfreebsd
sunsolaris
zabbixzabbix

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD