Vulnerability record · CVE-2011-3587 · published 10 October 2011
CVE-2011-3587: Zope p_ class remote command execution in Plone
Plone · Plone
Zope 2.12.x and 2.13.x, as shipped in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2, contains an unspecified flaw tied to the p_ class in OFS/misc_.py and the use of Python modules. A remote attacker can execute arbitrary commands on the server. The record gives no root-cause detail beyond the affected file and class, so the exact mechanism is not documented here.
Description
Unspecified vulnerability in Zope 2.12.x and 2.13.x, as used in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2, allows remote attackers to execute arbitrary commands via vectors related to the p_ class in OFS/misc_.py and the use of Python modules.
AV:N/AC:M/Au:N/C:C/I:C/A:C
Automated analysis
critical priorityRemote, unauthenticated command execution with a CVSS 2.0 base score of 9.3 and a very high EPSS percentile, though no KEV listing or confirmed public exploit is present in the record.
What it is
Zope 2.12.x and 2.13.x, as shipped in Plone 4.0.x through 4.0.9, 4.1, and 4.2 through 4.2a2, contains an unspecified flaw tied to the p_ class in OFS/misc_.py and the use of Python modules. A remote attacker can execute arbitrary commands on the server. The record gives no root-cause detail beyond the affected file and class, so the exact mechanism is not documented here.
Impact
Successful exploitation gives the attacker arbitrary command execution with the privileges of the Zope/Plone process, leading to full compromise of confidentiality, integrity and availability. No privilege escalation beyond that context is described.
Attack surface
Reachable over the network (AV:N) with no authentication required (Au:N), per the CVSS 2.0 vector. The vector rates access complexity as medium (AC:M), and the description does not state that user interaction is needed.
Exploitation
Not listed in CISA KEV and no ransomware use is documented. EPSS is very high (0.78079, 99.55th percentile), and all references are patch or vendor advisory links, so no public exploit code is confirmed by this record.
What to do
- Apply the vendor hotfix Products.PloneHotfix20110928 (Plone Hotfix 20110928) or the corresponding Zope patch referenced in the Zope security announcement.
- Upgrade or migrate off the affected Zope 2.12.x/2.13.x and Plone 4.0.x-4.2a2 releases to a supported, patched version.
- Restrict network access to the Zope/Plone instance to trusted clients where feasible, since the flaw is remotely reachable without authentication.
- Run the Zope/Plone service under a least-privilege account and sandbox it to limit the impact of command execution.
Detection
- Monitor Zope/Plone logs and web server access logs for requests that reference the p_ class or OFS/misc_.py in unexpected ways.
- Alert on child processes spawned by the Zope/Plone service, especially shells or interpreters, which would indicate command execution.
- Watch for outbound connections or file writes originating from the Zope/Plone process that are inconsistent with normal application behavior.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2011-3587 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2011-3587), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.