Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-2825

Опубликовано: 20 апр. 2018
Источник: nvd
CVSS3: 7
CVSS2: 6.8
EPSS Низкий

Описание

In the trapper functionality of Zabbix Server 2.4.x, specifically crafted trapper packets can pass database logic checks, resulting in database writes. An attacker can set up a Man-in-the-Middle server to alter trapper requests made between an active Zabbix proxy and Server to trigger this vulnerability.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:*
Версия от 2.4.0 (включая) до 2.4.8 (включая)
Конфигурация 2

Одно из

cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

EPSS

Процентиль: 70%
0.00626
Низкий

7 High

CVSS3

6.8 Medium

CVSS2

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

CVSS3: 7
ubuntu
почти 8 лет назад

In the trapper functionality of Zabbix Server 2.4.x, specifically crafted trapper packets can pass database logic checks, resulting in database writes. An attacker can set up a Man-in-the-Middle server to alter trapper requests made between an active Zabbix proxy and Server to trigger this vulnerability.

CVSS3: 7
debian
почти 8 лет назад

In the trapper functionality of Zabbix Server 2.4.x, specifically craf ...

CVSS3: 7
github
больше 3 лет назад

In the trapper functionality of Zabbix Server 2.4.x, specifically crafted trapper packets can pass database logic checks, resulting in database writes. An attacker can set up a Man-in-the-Middle server to alter trapper requests made between an active Zabbix proxy and Server to trigger this vulnerability.

EPSS

Процентиль: 70%
0.00626
Низкий

7 High

CVSS3

6.8 Medium

CVSS2

Дефекты

NVD-CWE-noinfo