PT-2017-15562 · Zabbix+3 · Zabbix Server+4

Published

2014-07-18

·

Updated

2022-06-15

·

CVE-2017-2824

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zabbix Server versions 2.4.X
Description A code execution issue exists in the trapper command functionality. It can be exploited by sending specially crafted packets, leading to command injection and remote code execution. An attacker can trigger this issue by making requests from an active Zabbix Proxy.
Recommendations For Zabbix Server version 2.4.X, consider disabling the trapper command functionality as a temporary workaround until a patch is available. Restrict access to the trapper command to minimize the risk of exploitation.

Exploit

Fix

RCE

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-1941
ALT-PU-2014-2165
ALT-PU-2016-1118
ALT-PU-2016-1167
ALT-PU-2016-1518
ALT-PU-2016-1782
ALT-PU-2016-1977
ALT-PU-2016-2058
ALT-PU-2017-2601
ALT-PU-2019-1862
ALT-PU-2020-1083
ALT-PU-2020-2718
ALT-PU-2020-3398
ALT-PU-2020-3446
ALT-PU-2021-2018
ALT-PU-2021-2156
CVE-2017-2824
DSA-3937-1
USN-4767-1

Affected Products

Alt Linux
Linuxmint
Ubuntu
Zabbix
Zabbix Server