// For flags

CVE-2017-2826

 

Severity Score

3.7
*CVSS v3

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

1
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

An information disclosure vulnerability exists in the iConfig proxy request of Zabbix server 2.4.X. A specially crafted iConfig proxy request can cause the Zabbix server to send the configuration information of any Zabbix proxy, resulting in information disclosure. An attacker can make requests from an active Zabbix proxy to trigger this vulnerability.

Existe una vulnerabilidad de divulgación de información en la petición del proxy iConfig en las versiones 2.4.X del servidor Zabbix. Una petición del proxy iConfig especialmente manipulada puede hacer que el servidor Zabbix envíe la información de configuración de cualquier proxy de Zabbix, lo que resulta en una divulgación de información. Un atacante puede realizar peticiones de un proxy Zabbix activo para desencadenar esta vulnerabilidad.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Medium
Authentication
None
Confidentiality
Partial
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2016-12-01 CVE Reserved
  • 2018-04-09 CVE Published
  • 2024-02-17 EPSS Updated
  • 2024-09-17 CVE Updated
  • 2024-09-17 First Exploit
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
CWE
  • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Zabbix
Search vendor "Zabbix"
Zabbix
Search vendor "Zabbix" for product "Zabbix"
2.4.0
Search vendor "Zabbix" for product "Zabbix" and version "2.4.0"
-
Affected
Zabbix
Search vendor "Zabbix"
Zabbix
Search vendor "Zabbix" for product "Zabbix"
2.4.0
Search vendor "Zabbix" for product "Zabbix" and version "2.4.0"
rc1
Affected
Zabbix
Search vendor "Zabbix"
Zabbix
Search vendor "Zabbix" for product "Zabbix"
2.4.0
Search vendor "Zabbix" for product "Zabbix" and version "2.4.0"
rc2
Affected
Zabbix
Search vendor "Zabbix"
Zabbix
Search vendor "Zabbix" for product "Zabbix"
2.4.0
Search vendor "Zabbix" for product "Zabbix" and version "2.4.0"
rc3
Affected
Zabbix
Search vendor "Zabbix"
Zabbix
Search vendor "Zabbix" for product "Zabbix"
2.4.1
Search vendor "Zabbix" for product "Zabbix" and version "2.4.1"
-
Affected
Zabbix
Search vendor "Zabbix"
Zabbix
Search vendor "Zabbix" for product "Zabbix"
2.4.1
Search vendor "Zabbix" for product "Zabbix" and version "2.4.1"
rc1
Affected
Zabbix
Search vendor "Zabbix"
Zabbix
Search vendor "Zabbix" for product "Zabbix"
2.4.1
Search vendor "Zabbix" for product "Zabbix" and version "2.4.1"
rc2
Affected
Zabbix
Search vendor "Zabbix"
Zabbix
Search vendor "Zabbix" for product "Zabbix"
2.4.2
Search vendor "Zabbix" for product "Zabbix" and version "2.4.2"
-
Affected
Zabbix
Search vendor "Zabbix"
Zabbix
Search vendor "Zabbix" for product "Zabbix"
2.4.2
Search vendor "Zabbix" for product "Zabbix" and version "2.4.2"
rc1
Affected
Zabbix
Search vendor "Zabbix"
Zabbix
Search vendor "Zabbix" for product "Zabbix"
2.4.3
Search vendor "Zabbix" for product "Zabbix" and version "2.4.3"
-
Affected
Zabbix
Search vendor "Zabbix"
Zabbix
Search vendor "Zabbix" for product "Zabbix"
2.4.3
Search vendor "Zabbix" for product "Zabbix" and version "2.4.3"
rc1
Affected
Zabbix
Search vendor "Zabbix"
Zabbix
Search vendor "Zabbix" for product "Zabbix"
2.4.4
Search vendor "Zabbix" for product "Zabbix" and version "2.4.4"
-
Affected
Zabbix
Search vendor "Zabbix"
Zabbix
Search vendor "Zabbix" for product "Zabbix"
2.4.4
Search vendor "Zabbix" for product "Zabbix" and version "2.4.4"
rc1
Affected
Zabbix
Search vendor "Zabbix"
Zabbix
Search vendor "Zabbix" for product "Zabbix"
2.4.5
Search vendor "Zabbix" for product "Zabbix" and version "2.4.5"
-
Affected
Zabbix
Search vendor "Zabbix"
Zabbix
Search vendor "Zabbix" for product "Zabbix"
2.4.5
Search vendor "Zabbix" for product "Zabbix" and version "2.4.5"
rc1
Affected
Zabbix
Search vendor "Zabbix"
Zabbix
Search vendor "Zabbix" for product "Zabbix"
2.4.6
Search vendor "Zabbix" for product "Zabbix" and version "2.4.6"
-
Affected
Zabbix
Search vendor "Zabbix"
Zabbix
Search vendor "Zabbix" for product "Zabbix"
2.4.6
Search vendor "Zabbix" for product "Zabbix" and version "2.4.6"
rc1
Affected
Zabbix
Search vendor "Zabbix"
Zabbix
Search vendor "Zabbix" for product "Zabbix"
2.4.7
Search vendor "Zabbix" for product "Zabbix" and version "2.4.7"
-
Affected
Zabbix
Search vendor "Zabbix"
Zabbix
Search vendor "Zabbix" for product "Zabbix"
2.4.7
Search vendor "Zabbix" for product "Zabbix" and version "2.4.7"
rc1
Affected
Zabbix
Search vendor "Zabbix"
Zabbix
Search vendor "Zabbix" for product "Zabbix"
2.4.8
Search vendor "Zabbix" for product "Zabbix" and version "2.4.8"
-
Affected
Zabbix
Search vendor "Zabbix"
Zabbix
Search vendor "Zabbix" for product "Zabbix"
2.4.8
Search vendor "Zabbix" for product "Zabbix" and version "2.4.8"
rc1
Affected
Zabbix
Search vendor "Zabbix"
Zabbix
Search vendor "Zabbix" for product "Zabbix"
2.4.9
Search vendor "Zabbix" for product "Zabbix" and version "2.4.9"
-
Affected
Zabbix
Search vendor "Zabbix"
Zabbix
Search vendor "Zabbix" for product "Zabbix"
2.4.9
Search vendor "Zabbix" for product "Zabbix" and version "2.4.9"
rc1
Affected
Debian
Search vendor "Debian"
Debian Linux
Search vendor "Debian" for product "Debian Linux"
8.0
Search vendor "Debian" for product "Debian Linux" and version "8.0"
-
Affected