PT-2013-3105 · Zabbix+1 · Zabbix+1

Pavels Jelisejevs

·

Published

2013-12-14

·

Updated

2021-07-20

·

CVE-2013-1364

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Zabbix versions prior to 1.8.16 Zabbix versions 2.x prior to 2.0.5rc1
Description The issue allows remote attackers to override LDAP configuration. This is achieved through the cnf parameter in the user.login function.
Recommendations For Zabbix versions prior to 1.8.16, update to version 1.8.16 or later. For Zabbix versions 2.x prior to 2.0.5rc1, update to version 2.0.5rc1 or later.

Fix

Improper Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2021-2282
CVE-2013-1364

Affected Products

Alt Linux
Zabbix