← Vulnerability feed

Vulnerability record · CVE-2013-3628 · published 7 February 2020

CVE-2013-3628: Zabbix 2.0.9 arbitrary command execution via injection flaw

Zabbix · Zabbix

Zabbix 2.0.9 contains an arbitrary command execution vulnerability classified as CWE-74 Injection. The record gives no detail on the vulnerable component or injection path, only that command execution is possible. Because Zabbix is a monitoring platform often run with elevated privileges, successful exploitation can compromise the server and the systems it monitors.

8.8 CVSS 3.1 High EPSS 67% · top 0.7% CWE-74 · Injection
8.8CVSS 3.1 base score, v2 6.5
67%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Zabbix 2.0.9 has an Arbitrary Command Execution Vulnerability

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityCVSS 8.8 with network reachability, high EPSS, and public exploit code make this a serious risk despite the low-privilege requirement.

What it is

Zabbix 2.0.9 contains an arbitrary command execution vulnerability classified as CWE-74 Injection. The record gives no detail on the vulnerable component or injection path, only that command execution is possible. Because Zabbix is a monitoring platform often run with elevated privileges, successful exploitation can compromise the server and the systems it monitors.

Impact

An attacker can execute arbitrary commands on the Zabbix server, gaining the privileges of the Zabbix process. This can lead to full compromise of the monitoring host and any credentials or managed endpoints it holds.

Attack surface

The CVSS vector is network-reachable (AV:N) with low attack complexity and no user interaction, but it requires low privileges (PR:L), meaning the attacker needs some authenticated access to the Zabbix interface or API. The exact injection entry point is not described in the record.

Exploitation

CISA KEV does not list this CVE, but EPSS is very high (0.67463, 99.27th percentile) and references include an Exploit tag plus Exploit-DB and Metasploit-related posts, indicating public exploit code exists.

What to do

  • Upgrade Zabbix to a current supported release; 2.0.9 is end-of-life and no longer receives security fixes.
  • Restrict network access to the Zabbix web interface and API to trusted management networks only.
  • Apply least privilege to Zabbix accounts and the Zabbix server process; avoid running it as root.
  • Monitor for and remove any unauthorized scripts or command execution paths in Zabbix configuration.
  • Review Zabbix audit logs for unexpected administrative or API activity.

Detection

  • Hunt for unexpected child processes spawned by the Zabbix server or web server (e.g., shell, curl, wget) using process creation telemetry.
  • Monitor Zabbix audit and web logs for anomalous API calls or script execution from low-privileged accounts.
  • Alert on outbound network connections from the Zabbix host to unusual destinations.
  • Search for known exploit artifacts or payloads associated with public Exploit-DB/Metasploit modules for this CVE.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2013-3628 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-23131Zabbix Frontend SAML SSO authentication bypass via session spoofingZabbix Frontend fails to verify the user login stored in the session when SAML SSO authentication is enabled, allowing session data to be modified. A…KEVEPSS 96%analysed5.3CVE-2022-23134Zabbix Frontend setup.php improper access control allows unauthenticated config changeAfter initial setup, some steps of Zabbix Frontend's setup.php remain reachable by unauthenticated users rather than only super-administrators. An at…KEVEPSS 95%analysed10.0CVE-2007-0640Zabbix vulnerabilityBuffer overflow in ZABBIX before 1.1.5 has unknown impact and attack vectors related to "SNMP IP addresses."EPSS 2.0%9.9CVE-2024-42327Zabbix frontend SQL injection in CUser addRelatedObjectsThe CUser.addRelatedObjects function in the Zabbix frontend contains an SQL injection reachable through the CUser.get API call. Any account with API …EPSS 79%analysed9.8CVE-2022-43516Microsoft windows firewall vulnerabilityA Firewall Rule which allows all incoming TCP connections to all programs from any source and to all ports is created in Windows Firewall after Zabbi…EPSS 0.95%9.8CVE-2020-11800Zabbix vulnerabilityZabbix Server 2.2.x and 3.0.x before 3.0.31, and 3.2 allows remote attackers to execute arbitrary code.EPSS 9.2%9.8CVE-2013-3738Zabbix improper input validation vulnerabilityA File Inclusion vulnerability exists in Zabbix 2.0.6 due to inadequate sanitization of request strings in CGI scripts, which could let a remote mali…EPSS 3.1%9.8CVE-2013-5743Zabbix SQL injection in multiple componentsZabbix versions 1.8.x before 1.8.18rc1, 2.0.x before 2.0.9rc1, and 2.1.x before 2.1.7 contain multiple SQL injection vulnerabilities. The record does…EPSS 80%analysed

Source: NIST National Vulnerability Database (record CVE-2013-3628), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.