Vulnerability Name: | CVE-2017-2826 (CCN-141345) | ||||||||||||||||||||||||||||||||||||
Assigned: | 2016-12-01 | ||||||||||||||||||||||||||||||||||||
Published: | 2018-04-09 | ||||||||||||||||||||||||||||||||||||
Updated: | 2019-03-13 | ||||||||||||||||||||||||||||||||||||
Summary: | An information disclosure vulnerability exists in the iConfig proxy request of Zabbix server 2.4.X. A specially crafted iConfig proxy request can cause the Zabbix server to send the configuration information of any Zabbix proxy, resulting in information disclosure. An attacker can make requests from an active Zabbix proxy to trigger this vulnerability. | ||||||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 3.7 Low (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N) 3.3 Low (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:U/RC:R)
3.3 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:U/RC:R)
| ||||||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N)
| ||||||||||||||||||||||||||||||||||||
Vulnerability Type: | CWE-200 | ||||||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2017-2826 Source: XF Type: UNKNOWN zabbix-cve20172826-info-disc(141345) Source: MLIST Type: Mailing List, Third Party Advisory [debian-lts-announce] 20190311 [SECURITY] [DLA 1708-1] zabbix security update Source: MISC Type: Exploit, Third Party Advisory https://talosintelligence.com/vulnerability_reports/TALOS-2017-0327 Source: CCN Type: Talos Vulnerability Report TALOS-2017-0327 Zabbix Server Config Proxy Request Information Disclosure Vulnerability Source: CCN Type: Zabbix Web site Zabbix Server | ||||||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration 2: Denotes that component is vulnerable | ||||||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||
BACK |