CVE-2017-2826
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
An information disclosure vulnerability exists in the iConfig proxy request of Zabbix server 2.4.X. A specially crafted iConfig proxy request can cause the Zabbix server to send the configuration information of any Zabbix proxy, resulting in information disclosure. An attacker can make requests from an active Zabbix proxy to trigger this vulnerability.
Existe una vulnerabilidad de divulgación de información en la petición del proxy iConfig en las versiones 2.4.X del servidor Zabbix. Una petición del proxy iConfig especialmente manipulada puede hacer que el servidor Zabbix envíe la información de configuración de cualquier proxy de Zabbix, lo que resulta en una divulgación de información. Un atacante puede realizar peticiones de un proxy Zabbix activo para desencadenar esta vulnerabilidad.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2016-12-01 CVE Reserved
- 2018-04-09 CVE Published
- 2024-02-17 EPSS Updated
- 2024-09-17 CVE Updated
- 2024-09-17 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://lists.debian.org/debian-lts-announce/2019/03/msg00010.html | Mailing List |
URL | Date | SRC |
---|---|---|
https://talosintelligence.com/vulnerability_reports/TALOS-2017-0327 | 2024-09-17 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Zabbix Search vendor "Zabbix" | Zabbix Search vendor "Zabbix" for product "Zabbix" | 2.4.0 Search vendor "Zabbix" for product "Zabbix" and version "2.4.0" | - |
Affected
| ||||||
Zabbix Search vendor "Zabbix" | Zabbix Search vendor "Zabbix" for product "Zabbix" | 2.4.0 Search vendor "Zabbix" for product "Zabbix" and version "2.4.0" | rc1 |
Affected
| ||||||
Zabbix Search vendor "Zabbix" | Zabbix Search vendor "Zabbix" for product "Zabbix" | 2.4.0 Search vendor "Zabbix" for product "Zabbix" and version "2.4.0" | rc2 |
Affected
| ||||||
Zabbix Search vendor "Zabbix" | Zabbix Search vendor "Zabbix" for product "Zabbix" | 2.4.0 Search vendor "Zabbix" for product "Zabbix" and version "2.4.0" | rc3 |
Affected
| ||||||
Zabbix Search vendor "Zabbix" | Zabbix Search vendor "Zabbix" for product "Zabbix" | 2.4.1 Search vendor "Zabbix" for product "Zabbix" and version "2.4.1" | - |
Affected
| ||||||
Zabbix Search vendor "Zabbix" | Zabbix Search vendor "Zabbix" for product "Zabbix" | 2.4.1 Search vendor "Zabbix" for product "Zabbix" and version "2.4.1" | rc1 |
Affected
| ||||||
Zabbix Search vendor "Zabbix" | Zabbix Search vendor "Zabbix" for product "Zabbix" | 2.4.1 Search vendor "Zabbix" for product "Zabbix" and version "2.4.1" | rc2 |
Affected
| ||||||
Zabbix Search vendor "Zabbix" | Zabbix Search vendor "Zabbix" for product "Zabbix" | 2.4.2 Search vendor "Zabbix" for product "Zabbix" and version "2.4.2" | - |
Affected
| ||||||
Zabbix Search vendor "Zabbix" | Zabbix Search vendor "Zabbix" for product "Zabbix" | 2.4.2 Search vendor "Zabbix" for product "Zabbix" and version "2.4.2" | rc1 |
Affected
| ||||||
Zabbix Search vendor "Zabbix" | Zabbix Search vendor "Zabbix" for product "Zabbix" | 2.4.3 Search vendor "Zabbix" for product "Zabbix" and version "2.4.3" | - |
Affected
| ||||||
Zabbix Search vendor "Zabbix" | Zabbix Search vendor "Zabbix" for product "Zabbix" | 2.4.3 Search vendor "Zabbix" for product "Zabbix" and version "2.4.3" | rc1 |
Affected
| ||||||
Zabbix Search vendor "Zabbix" | Zabbix Search vendor "Zabbix" for product "Zabbix" | 2.4.4 Search vendor "Zabbix" for product "Zabbix" and version "2.4.4" | - |
Affected
| ||||||
Zabbix Search vendor "Zabbix" | Zabbix Search vendor "Zabbix" for product "Zabbix" | 2.4.4 Search vendor "Zabbix" for product "Zabbix" and version "2.4.4" | rc1 |
Affected
| ||||||
Zabbix Search vendor "Zabbix" | Zabbix Search vendor "Zabbix" for product "Zabbix" | 2.4.5 Search vendor "Zabbix" for product "Zabbix" and version "2.4.5" | - |
Affected
| ||||||
Zabbix Search vendor "Zabbix" | Zabbix Search vendor "Zabbix" for product "Zabbix" | 2.4.5 Search vendor "Zabbix" for product "Zabbix" and version "2.4.5" | rc1 |
Affected
| ||||||
Zabbix Search vendor "Zabbix" | Zabbix Search vendor "Zabbix" for product "Zabbix" | 2.4.6 Search vendor "Zabbix" for product "Zabbix" and version "2.4.6" | - |
Affected
| ||||||
Zabbix Search vendor "Zabbix" | Zabbix Search vendor "Zabbix" for product "Zabbix" | 2.4.6 Search vendor "Zabbix" for product "Zabbix" and version "2.4.6" | rc1 |
Affected
| ||||||
Zabbix Search vendor "Zabbix" | Zabbix Search vendor "Zabbix" for product "Zabbix" | 2.4.7 Search vendor "Zabbix" for product "Zabbix" and version "2.4.7" | - |
Affected
| ||||||
Zabbix Search vendor "Zabbix" | Zabbix Search vendor "Zabbix" for product "Zabbix" | 2.4.7 Search vendor "Zabbix" for product "Zabbix" and version "2.4.7" | rc1 |
Affected
| ||||||
Zabbix Search vendor "Zabbix" | Zabbix Search vendor "Zabbix" for product "Zabbix" | 2.4.8 Search vendor "Zabbix" for product "Zabbix" and version "2.4.8" | - |
Affected
| ||||||
Zabbix Search vendor "Zabbix" | Zabbix Search vendor "Zabbix" for product "Zabbix" | 2.4.8 Search vendor "Zabbix" for product "Zabbix" and version "2.4.8" | rc1 |
Affected
| ||||||
Zabbix Search vendor "Zabbix" | Zabbix Search vendor "Zabbix" for product "Zabbix" | 2.4.9 Search vendor "Zabbix" for product "Zabbix" and version "2.4.9" | - |
Affected
| ||||||
Zabbix Search vendor "Zabbix" | Zabbix Search vendor "Zabbix" for product "Zabbix" | 2.4.9 Search vendor "Zabbix" for product "Zabbix" and version "2.4.9" | rc1 |
Affected
| ||||||
Debian Search vendor "Debian" | Debian Linux Search vendor "Debian" for product "Debian Linux" | 8.0 Search vendor "Debian" for product "Debian Linux" and version "8.0" | - |
Affected
|