Home

Description

Zenoss Core 3.x contains a command injection vulnerability in the showDaemonXMLConfig endpoint. The daemon parameter is passed directly to a Popen() call in ZenossInfo.py without proper sanitation, allowing authenticated users to execute arbitrary commands on the server as the zenoss user.

PUBLISHED Reserved 2025-08-08 | Published 2025-08-08 | Updated 2026-04-07 | Assigner VulnCheck




HIGH: 8.7CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Problem types

CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

Product status

Default status
unaffected

3.0
affected

Credits

bcoles finder

References

www.exploit-db.com/exploits/20205 exploit

raw.githubusercontent.com/...oss_showdaemonxmlconfig_exec.rb exploit

www.exploit-db.com/exploits/37571 exploit

web.archive.org/...-3.2.1-multiple-security-vulnerabilities/ technical-description exploit

sourceforge.net/projects/zenoss/ product

www.vulncheck.com/advisories/zenoss-command-execution third-party-advisory

cve.org (CVE-2012-10048)

nvd.nist.gov (CVE-2012-10048)

Download JSON