← Vulnerability feed

Vulnerability record · CVE-2001-0800 · published 6 December 2001

CVE-2001-0800: IRIX lpsched remote command execution via shell metacharacters

Sgi · Irix

The IRIX print scheduler lpsched fails to neutralize shell metacharacters in input, allowing remote attackers to run arbitrary commands. The flaw affects IRIX 6.5.13f and earlier and carries a maximum CVSS v2 score of 10, so any reachable host is fully exposed.

10.0 CVSS 2.0 High EPSS 54% · top 1.0%
10.0CVSS 2.0 base score
54%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
16 Jun 2026Last modified by NVD

Description

lpsched in IRIX 6.5.13f and earlier allows remote attackers to execute arbitrary commands via shell metacharacters.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

critical priorityCVSS v2 score of 10 with network reachability, no authentication and complete impact, plus high EPSS, makes this a top-priority exposure despite the absence of KEV listing.

What it is

The IRIX print scheduler lpsched fails to neutralize shell metacharacters in input, allowing remote attackers to run arbitrary commands. The flaw affects IRIX 6.5.13f and earlier and carries a maximum CVSS v2 score of 10, so any reachable host is fully exposed.

Impact

An attacker gains arbitrary command execution on the target host, typically with the privileges of the lpsched process, which can lead to full system compromise given the CVSS impact ratings of complete confidentiality, integrity and availability loss.

Attack surface

Reachable over the network (AV:N) with no authentication (Au:N) and no user interaction, per the CVSS v2 vector; the attack targets the lpsched service listening on the host.

Exploitation

Not listed in CISA KEV and no ransomware associations are documented, but EPSS is high at roughly 0.54 (99th percentile) and a public exploit reference exists, indicating meaningful real-world exploitation likelihood.

What to do

  • Apply the SGI vendor patch referenced in advisory 20011003-02-P as the first action.
  • If patching is not possible, restrict network access to the lpsched service to trusted hosts only.
  • Disable or stop the lpsched service on systems that do not require printing.
  • Segment or firewall legacy IRIX 6.5.13f and earlier hosts from untrusted networks.
  • Monitor vendor advisories for any updated guidance for end-of-life IRIX systems.

Detection

  • Inspect lpsched logs and process accounting for unexpected child processes or shell invocations spawned by the scheduler.
  • Alert on network connections to the lpsched service from untrusted or unexpected source addresses.
  • Hunt for shell metacharacter patterns (such as ;, |, backticks, $()) in print job or scheduler input reaching lpsched.
  • Correlate process creation events on IRIX hosts with lpsched as the parent for suspicious command lines.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2001-0800 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2010-1039Hp nfs\/oncplus vulnerabilityFormat string vulnerability in the _msgout function in rpc.pcnfsd in IBM AIX 6.1, 5.3, and earlier; IBM VIOS 2.1, 1.5, and earlier; NFS/ONCplus B.11.…EPSS 20%10.0CVE-2004-0139Sgi irix vulnerabilityUnknown vulnerability in the bsd.a kernel networking for SGI IRIX 6.5.22 through 6.5.25, and possibly earlier versions, in which "t_unbind changes t_…EPSS 1.7%10.0CVE-2003-0694Sendmail prescan buffer overflow allows remote code executionThe prescan function in Sendmail 8.12.9 contains a buffer overflow reachable through crafted email addresses, as demonstrated via the parseaddr funct…EPSS 66%analysed10.0CVE-2003-0575Sgi irix vulnerabilityHeap-based buffer overflow in the name services daemon (nsd) in SGI IRIX 6.5.x through 6.5.21f, and possibly earlier versions, allows attackers to ga…EPSS 2.9%10.0CVE-2003-0473Sgi irix vulnerabilityUnknown vulnerability in the IPv6 capability in IRIX 6.5.19 causes snoop to process packets as the root user, with unknown implications.EPSS 2.3%10.0CVE-2002-1584Sgi irix vulnerabilityUnknown vulnerability in the AUTH_DES authentication for RPC in Solaris 2.5.1, 2.6, and 7, SGI IRIX 6.5 to 6.5.19f, and possibly other platforms, all…EPSS 5.7%10.0CVE-2002-1318Samba encrypted password decryption buffer overflowSamba 2.2.2 through 2.2.6 contains a buffer overflow that occurs when an encrypted password is decrypted and a DOS codepage string is converted to li…EPSS 52%analysed10.0CVE-2002-0359Sgi irix vulnerabilityxfsmd for IRIX 6.5 through 6.5.16 uses weak authentication, which allows remote attackers to call dangerous RPC functions, including those that can m…EPSS 3.6%

Source: NIST National Vulnerability Database (record CVE-2001-0800), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.