CVE-2012-10048 describes a command injection vulnerability in Zenoss Core 3.x, specifically within the showDaemonXMLConfig endpoint. An authenticated attacker can exploit this by injecting arbitrary commands into the 'daemon' parameter, which is directly passed to a Popen() call in ZenossInfo.py without proper sanitization. This allows for remote code execution on the server as the zenoss user. The vulnerability carries a high CVSS score of 8.7, indicating a severe risk. It is easily exploitable over the network with low attack complexity and requires only low privileges, leading to high impacts on confidentiality, integrity, and availability. The EPSS score and FAUCET Risk Score further emphasize its significant threat potential. While not listed on the CISA KEV catalog, exploit intelligence confirms the existence of a Metasploit module for this vulnerability, indicating readily available exploit code. Community discussion is notably high, suggesting significant awareness and interest among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Zenoss, Inc. | Zenoss Core | 3.0CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.