HIGH
Zenoss 3.x showDaemonXMLConfig Command Execution
Published Aug 8, 2025
8.7
HIGHCVSS 4.0
EPSS 3.72%
Description
Zenoss Core 3.x contains a command injection vulnerability in the showDaemonXMLConfig endpoint. The daemon parameter is passed directly to a Popen() call in ZenossInfo.py without proper sanitation, allowing authenticated users to execute arbitrary commands on the server as the zenoss user.
Affected products
-
- Version 3.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Zenoss, Inc. | Zenoss Core | unaffected |
|
No data.
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (7)
- http://web.archive.org/web/20221203180334/https://itsecuritysolutions.org/2012-07-30-zenoss-3.2.1-multiple-security-vulnerabilities/ technical-descriptionexploit
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2012-6595 Advisory
- https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/linux/http/zenoss_showdaemonxmlconfig_exec.rb exploit
- https://sourceforge.net/projects/zenoss/ product
- https://www.exploit-db.com/exploits/20205 exploit
- https://www.exploit-db.com/exploits/37571 exploit
- https://www.vulncheck.com/advisories/zenoss-command-execution third-party-advisory
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner VulnCheck
Published Aug 8, 2025
Updated Apr 7, 2026
Reserved Aug 8, 2025
Link CVE-2012-10048
CISA Vulnrichment
Updated Aug 8, 2025
ENISA EUVD
EUVD-2012-6595 Assigner VulnCheck
Published Aug 8, 2025
Updated Apr 7, 2026
Exploited since n/a
Link EUVD-2012-6595