Vulnerability record · CVE-2020-7209 · published 13 February 2020
CVE-2020-7209: HP LinuxKI remote code execution via command injection
Hp · Linuxki
LinuxKI v6.0-1 and earlier contains a remote code execution flaw, fixed in release 6.0-2. The record gives no root-cause detail beyond the CWE being unspecified, but the CVSS vector and public exploit write-ups indicate a network-reachable command injection. Because the tool is a Linux diagnostic/performance toolkit, successful exploitation gives an attacker code execution in the context of the LinuxKI service or user.
Description
LinuxKI v6.0-1 and earlier is vulnerable to an remote code execution which is resolved in release 6.0-2.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network, unauthenticated, no-interaction exploitation and public exploit code, though it is not in KEV.
What it is
LinuxKI v6.0-1 and earlier contains a remote code execution flaw, fixed in release 6.0-2. The record gives no root-cause detail beyond the CWE being unspecified, but the CVSS vector and public exploit write-ups indicate a network-reachable command injection. Because the tool is a Linux diagnostic/performance toolkit, successful exploitation gives an attacker code execution in the context of the LinuxKI service or user.
Impact
An unauthenticated remote attacker can execute arbitrary commands on the host running the vulnerable LinuxKI version, leading to full compromise of confidentiality, integrity and availability.
Attack surface
Reached over the network with no authentication and no user interaction required, per the CVSS vector AV:N/AC:L/PR:N/UI:N. The exact exposed endpoint or parameter is not described in the record.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.98751, 99.9th percentile) and multiple Packet Storm references are tagged Exploit, indicating public exploit code exists.
What to do
- Upgrade LinuxKI to release 6.0-2 or later immediately.
- If upgrade is not possible, remove or restrict network access to the LinuxKI service using host firewalls or network segmentation.
- Run LinuxKI with the least privilege necessary and avoid exposing it on untrusted networks.
- Monitor vendor and Packet Storm advisories for updated guidance on the affected component.
Detection
- Search process and command-line telemetry on LinuxKI hosts for unexpected shell or interpreter invocations spawned by the LinuxKI process.
- Review web or service access logs for anomalous requests to LinuxKI endpoints, especially those containing shell metacharacters.
- Alert on outbound network connections or file writes originating from the LinuxKI service account.
- Inventory hosts running LinuxKI and confirm version is 6.0-2 or later.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://packetstormsecurity.com/files/157739/HP-LinuxKI-6.01-Remote-Command-Injection.html | ExploitThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/158025/LinuxKI-Toolset-6.01-Remote-Command-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://github.com/HewlettPackard/LinuxKI/releases/tag/v6.0-2 | Third Party Advisory |
| http://packetstormsecurity.com/files/157739/HP-LinuxKI-6.01-Remote-Command-Injection.html | ExploitThird Party AdvisoryVDB Entry |
| http://packetstormsecurity.com/files/158025/LinuxKI-Toolset-6.01-Remote-Command-Execution.html | ExploitThird Party AdvisoryVDB Entry |
| https://github.com/HewlettPackard/LinuxKI/releases/tag/v6.0-2 | Third Party Advisory |
Track CVE-2020-7209 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-7209), CISA KEV, FIRST EPSS (scores of 2026-09-25). This page is refreshed as NVD updates the record.