PT-2009-2751 · Ca · Ca Service Metric Analysis+1

Michel Arboi

·

Published

2009-01-08

·

Updated

2018-10-11

·

CVE-2009-0043

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions CA Service Metric Analysis versions r11.0 through r11.1 SP1 CA Service Level Management version 3.5
Description The issue is related to the smmsnmpd service, which does not properly restrict access. This allows remote attackers to execute arbitrary commands.
Recommendations For CA Service Metric Analysis versions r11.0 through r11.1 SP1, update to a version that properly restricts access to the smmsnmpd service. For CA Service Level Management version 3.5, update to a version that properly restricts access to the smmsnmpd service. As a temporary workaround, consider restricting access to the smmsnmpd service until a patch is available.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-0043

Affected Products

Ca Service Level Management
Ca Service Metric Analysis