Vulnerability record · CVE-2009-0043 · published 8 January 2009
CVE-2009-0043: CA Service Metric Analysis smmsnmpd access control flaw allows command execution
CCa · Service Level Management
The smmsnmpd service in CA Service Metric Analysis r11.0 through r11.1 SP1 and Service Level Management 3.5 does not properly restrict access, allowing remote attackers to execute arbitrary commands through unspecified vectors. The flaw is an access control weakness (CWE-264) in a network-exposed service, and the vendor has published a patch.
Description
The smmsnmpd service in CA Service Metric Analysis r11.0 through r11.1 SP1 and Service Level Management 3.5 does not properly restrict access, which allows remote attackers to execute arbitrary commands via unspecified vectors.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
high priorityThe flaw allows unauthenticated remote command execution with a CVSS 2.0 base score of 10 and high EPSS, though no known in-the-wild exploitation is documented and a patch is available.
What it is
The smmsnmpd service in CA Service Metric Analysis r11.0 through r11.1 SP1 and Service Level Management 3.5 does not properly restrict access, allowing remote attackers to execute arbitrary commands through unspecified vectors. The flaw is an access control weakness (CWE-264) in a network-exposed service, and the vendor has published a patch.
Impact
A remote attacker can execute arbitrary commands on the affected host, which given the CVSS 2.0 vector (AV:N/AC:L/Au:N/C:C/I:C/A:C) implies full compromise of confidentiality, integrity and availability.
Attack surface
The service is reachable over the network (AV:N) with no authentication required (Au:N) and low attack complexity (AC:L). No user interaction is indicated by the vector or description.
Exploitation
The record is not listed in CISA KEV and no public exploit or ransomware usage is documented; EPSS is high at roughly 0.53 (99th percentile), suggesting elevated likelihood of attempted exploitation. Reference tags include Patch and Vendor Advisory, so a fix exists.
What to do
- Apply the vendor patch referenced in the CA advisory and support article (contentID=196148) for Service Metric Analysis r11.0 through r11.1 SP1 and Service Level Management 3.5.
- Restrict network access to the smmsnmpd service using firewall rules or network segmentation so only trusted management hosts can reach it.
- Disable or stop the smmsnmpd service if it is not required for operations.
- Monitor vendor advisories for updated guidance and confirm the installed version is covered by the patch.
- Audit access controls on the service and any related management interfaces for unintended exposure.
Detection
- Monitor network traffic to the smmsnmpd service port for connections from unexpected or untrusted sources.
- Review host and service logs for command execution or process spawning anomalies originating from the smmsnmpd process.
- Alert on firewall or IDS events targeting the smmsnmpd service, especially repeated connection attempts from external addresses.
- Baseline normal smmsnmpd traffic and flag deviations in volume, source, or payload patterns.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2009-0043 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2009-0043), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.