PT-2020-4299 · Zabbix+4 · Zabbix Server+5

Fu Chuang

·

Published

2016-10-03

·

Updated

2022-06-15

·

CVE-2020-11800

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Zabbix Server versions 2.2.x through 3.2.x Zabbix Server versions 3.0.x through 3.0.30
Description: The issue is related to errors in code generation management in the Zabbix monitoring system. It allows a remote attacker to execute arbitrary code.
Recommendations: For Zabbix Server versions 2.2.x through 3.0.30, update to version 3.0.31 or later. For Zabbix Server version 3.2, consider disabling the vulnerable code generation management functionality until a patch is available. Restrict access to the Zabbix Server to minimize the risk of exploitation.

Fix

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2016-2058
BDU:2020-04792
CVE-2020-11800
DLA-2461-1
OPENSUSE-SU-2020:1604-1
OPENSUSE-SU-2020_1604-1
USN-4767-1

Affected Products

Alt Linux
Linuxmint
Suse
Ubuntu
Zabbix
Zabbix Server