Zabbix User Spoofing Vulnerability
BID:65402
Info
Zabbix User Spoofing Vulnerability
| Bugtraq ID: | 65402 |
| Class: | Design Error |
| CVE: |
CVE-2014-1682 |
| Remote: | Yes |
| Local: | No |
| Published: | Feb 04 2014 12:00AM |
| Updated: | Apr 13 2015 09:15PM |
| Credit: | Vitaly Shupak |
| Vulnerable: |
ZABBIX ZABBIX 2.2.1 ZABBIX ZABBIX 2.0.10 ZABBIX ZABBIX 1.8.19 |
| Not Vulnerable: | |
Discussion
Zabbix User Spoofing Vulnerability
Zabbix is prone to a security vulnerability that may allow attackers to conduct spoofing attacks.
Attackers can exploit this issue to spoof and impersonate a legitimate user, Other attacks are also possible.
Zabbix 1.8.19, 2.0.10, and 2.2.1 are vulnerable.
Zabbix is prone to a security vulnerability that may allow attackers to conduct spoofing attacks.
Attackers can exploit this issue to spoof and impersonate a legitimate user, Other attacks are also possible.
Zabbix 1.8.19, 2.0.10, and 2.2.1 are vulnerable.
Exploit / POC
Zabbix User Spoofing Vulnerability
Attackers can use readily available tools to exploit this issue.
Attackers can use readily available tools to exploit this issue.
Solution / Fix
Zabbix User Spoofing Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Zabbix User Spoofing Vulnerability
References:
References:
- Zabbix 1.8.20rc1 (Release Candidate). (ZABBIX )
- Zabbix 2.0.11rc1 (Release Candidate). (ZABBIX)
- ZABBIX HomePage (ZABBIX)
- Security flaw with API access when using HTTP authentication (ZABBIX)
- Zabbix 2.2.2rc1 (Release Candidate). (ZABBIX)