CVE-2011-2653 EXPLOIT
10.0
HIGH · CVSS 2.0 · EPSS 72.5% (pctl 99)
Patch early
A public exploit exists.
Description
Directory traversal vulnerability in the rtrlet component in Novell ZENworks Asset Management (ZAM) 7.5 allows remote attackers to execute arbitrary code by uploading an executable file.
Scoring
| CVSS | 10.0 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
| EPSS | 72.49% — more likely to be exploited than 99% of all CVEs |
| Weakness | CWE-22 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2011-12-08 |
| Last modified | 2026-06-16 |
Affected (1)
| Vendor | Product |
|---|---|
| novell | zenworks asset management |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | Novell ZENworks Asset Management - Remote Execution (Metasploit) | 2012-08-15 |
References
→ the Explorer · watch your stack · NVD