CVE-2012-6086 — Zabbix vulnerability
Severity
4.3MEDIUMNVD
EPSS
0.2%
top 58.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 29
Latest updateMay 17
Description
libs/zbxmedia/eztexting.c in Zabbix 1.8.x before 1.8.18rc1, 2.0.x before 2.0.8rc1, and 2.1.x before 2.1.2 does not properly set the CURLOPT_SSL_VERIFYHOST option for libcurl, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
CVSS vector
AV:N/AC:M/C:N/I:P/A:NExploitability: 8.6 | Impact: 2.9
Affected Packages3 packages
🔴Vulnerability Details
2📋Vendor Advisories
1Debian▶
CVE-2012-6086: zabbix - libs/zbxmedia/eztexting.c in Zabbix 1.8.x before 1.8.18rc1, 2.0.x before 2.0.8rc...↗2012
💬Community
4Bugzilla▶
CVE-2012-6086 zabbix20: Improper use of cURL API might lead to improper SSL certificate verification (MiTM) [epel-6]↗2013-01-09
Bugzilla▶
CVE-2012-6086 zabbix: Improper use of cURL API might lead to improper SSL certificate verification (MiTM) [fedora-all]↗2013-01-07
Bugzilla▶
CVE-2012-6086 zabbix: Improper use of cURL API might lead to improper SSL certificate verification (MiTM) [epel-6]↗2013-01-07
Bugzilla▶
CVE-2012-6086 zabbix: Improper use of cURL API might lead to improper SSL certificate verification (MiTM)↗2013-01-07