← Vulnerability feed

Vulnerability record · CVE-2009-0043 · published 8 January 2009

CVE-2009-0043: CA Service Metric Analysis smmsnmpd access control flaw allows command execution

CCa · Service Level Management

The smmsnmpd service in CA Service Metric Analysis r11.0 through r11.1 SP1 and Service Level Management 3.5 does not properly restrict access, allowing remote attackers to execute arbitrary commands through unspecified vectors. The flaw is an access control weakness (CWE-264) in a network-exposed service, and the vendor has published a patch.

10.0 CVSS 2.0 High EPSS 53% · top 1.0% CWE-264 · Permissions and access controls
10.0CVSS 2.0 base score
53%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
12References
16 Jun 2026Last modified by NVD

Description

The smmsnmpd service in CA Service Metric Analysis r11.0 through r11.1 SP1 and Service Level Management 3.5 does not properly restrict access, which allows remote attackers to execute arbitrary commands via unspecified vectors.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityThe flaw allows unauthenticated remote command execution with a CVSS 2.0 base score of 10 and high EPSS, though no known in-the-wild exploitation is documented and a patch is available.

What it is

The smmsnmpd service in CA Service Metric Analysis r11.0 through r11.1 SP1 and Service Level Management 3.5 does not properly restrict access, allowing remote attackers to execute arbitrary commands through unspecified vectors. The flaw is an access control weakness (CWE-264) in a network-exposed service, and the vendor has published a patch.

Impact

A remote attacker can execute arbitrary commands on the affected host, which given the CVSS 2.0 vector (AV:N/AC:L/Au:N/C:C/I:C/A:C) implies full compromise of confidentiality, integrity and availability.

Attack surface

The service is reachable over the network (AV:N) with no authentication required (Au:N) and low attack complexity (AC:L). No user interaction is indicated by the vector or description.

Exploitation

The record is not listed in CISA KEV and no public exploit or ransomware usage is documented; EPSS is high at roughly 0.53 (99th percentile), suggesting elevated likelihood of attempted exploitation. Reference tags include Patch and Vendor Advisory, so a fix exists.

What to do

  • Apply the vendor patch referenced in the CA advisory and support article (contentID=196148) for Service Metric Analysis r11.0 through r11.1 SP1 and Service Level Management 3.5.
  • Restrict network access to the smmsnmpd service using firewall rules or network segmentation so only trusted management hosts can reach it.
  • Disable or stop the smmsnmpd service if it is not required for operations.
  • Monitor vendor advisories for updated guidance and confirm the installed version is covered by the patch.
  • Audit access controls on the service and any related management interfaces for unintended exposure.

Detection

  • Monitor network traffic to the smmsnmpd service port for connections from unexpected or untrusted sources.
  • Review host and service logs for command execution or process spawning anomalies originating from the smmsnmpd process.
  • Alert on firewall or IDS events targeting the smmsnmpd service, especially repeated connection attempts from external addresses.
  • Baseline normal smmsnmpd traffic and flag deviations in volume, source, or payload patterns.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2009-0043 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2009-0043), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.