ZeroHour

CVE-2017-2826

PoC
CVSS 3.0
3.7 low
EPSS
3%p88
Published
()
Modified
Description

An information disclosure vulnerability exists in the iConfig proxy request of Zabbix server 2.4.X. A specially crafted iConfig proxy request can cause the Zabbix server to send the configuration information of any Zabbix proxy, resulting in information disclosure. An attacker can make requests from an active Zabbix proxy to trigger this vulnerability.

Vendors
zabbixdebian
Products
zabbix, debian linux
Weakness
CWE-200
Vector
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.