Vulnerability record · CVE-2013-3628 · published 7 February 2020
CVE-2013-3628: Zabbix 2.0.9 arbitrary command execution via injection flaw
Zabbix · Zabbix
Zabbix 2.0.9 contains an arbitrary command execution vulnerability classified as CWE-74 Injection. The record gives no detail on the vulnerable component or injection path, only that command execution is possible. Because Zabbix is a monitoring platform often run with elevated privileges, successful exploitation can compromise the server and the systems it monitors.
Description
Zabbix 2.0.9 has an Arbitrary Command Execution Vulnerability
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with network reachability, high EPSS, and public exploit code make this a serious risk despite the low-privilege requirement.
What it is
Zabbix 2.0.9 contains an arbitrary command execution vulnerability classified as CWE-74 Injection. The record gives no detail on the vulnerable component or injection path, only that command execution is possible. Because Zabbix is a monitoring platform often run with elevated privileges, successful exploitation can compromise the server and the systems it monitors.
Impact
An attacker can execute arbitrary commands on the Zabbix server, gaining the privileges of the Zabbix process. This can lead to full compromise of the monitoring host and any credentials or managed endpoints it holds.
Attack surface
The CVSS vector is network-reachable (AV:N) with low attack complexity and no user interaction, but it requires low privileges (PR:L), meaning the attacker needs some authenticated access to the Zabbix interface or API. The exact injection entry point is not described in the record.
Exploitation
CISA KEV does not list this CVE, but EPSS is very high (0.67463, 99.27th percentile) and references include an Exploit tag plus Exploit-DB and Metasploit-related posts, indicating public exploit code exists.
What to do
- Upgrade Zabbix to a current supported release; 2.0.9 is end-of-life and no longer receives security fixes.
- Restrict network access to the Zabbix web interface and API to trusted management networks only.
- Apply least privilege to Zabbix accounts and the Zabbix server process; avoid running it as root.
- Monitor for and remove any unauthorized scripts or command execution paths in Zabbix configuration.
- Review Zabbix audit logs for unexpected administrative or API activity.
Detection
- Hunt for unexpected child processes spawned by the Zabbix server or web server (e.g., shell, curl, wget) using process creation telemetry.
- Monitor Zabbix audit and web logs for anomalous API calls or script execution from low-privileged accounts.
- Alert on outbound network connections from the Zabbix host to unusual destinations.
- Search for known exploit artifacts or payloads associated with public Exploit-DB/Metasploit modules for this CVE.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.exploit-db.com/exploits/29321 | Third Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/63453 | Third Party AdvisoryVDB Entry |
| https://community.rapid7.com/community/metasploit/blog/2013/10/30/seven-foss-disclosures-part-one | Third Party Advisory |
| https://community.rapid7.com/community/metasploit/blog/2013/10/30/seven-tricks-and-treats | ExploitThird Party Advisory |
| http://www.exploit-db.com/exploits/29321 | Third Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/63453 | Third Party AdvisoryVDB Entry |
| https://community.rapid7.com/community/metasploit/blog/2013/10/30/seven-foss-disclosures-part-one | Third Party Advisory |
| https://community.rapid7.com/community/metasploit/blog/2013/10/30/seven-tricks-and-treats | ExploitThird Party Advisory |
Track CVE-2013-3628 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2013-3628), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.