cbcvebase.
CVE-2017-2825
published 2018-04-20

CVE-2017-2825: In the trapper functionality of Zabbix Server 2.4.x, specifically crafted trapper packets can pass database logic checks, resulting in database writes. An…

PriorityP339high7CVSS 3.0
AVNACHPRNUINSUCLIHAL
EPSS
4.38%
90.2th percentile
In the trapper functionality of Zabbix Server 2.4.x, specifically crafted trapper packets can pass database logic checks, resulting in database writes. An attacker can set up a Man-in-the-Middle server to alter trapper requests made between an active Zabbix proxy and Server to trigger this vulnerability.

Affected

13 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debianzabbix< zabbix 1:3.0.7+dfsg-3 (bookworm)zabbix 1:3.0.7+dfsg-3 (bookworm)
taloszabbix
zabbixzabbix>= 0 < 1:3.0.7+dfsg-31:3.0.7+dfsg-3
zabbixzabbix>= 0 < 1:3.0.7+dfsg-31:3.0.7+dfsg-3
zabbixzabbix>= 0 < 1:3.0.7+dfsg-31:3.0.7+dfsg-3
zabbixzabbix>= 0 < 1:3.0.7+dfsg-31:3.0.7+dfsg-3
zabbixzabbix>= 0 < 1:2.2.2+dfsg-1ubuntu1+esm41:2.2.2+dfsg-1ubuntu1+esm4
zabbixzabbix>= 0 < 1:2.4.7+dfsg-2ubuntu2.1+esm31:2.4.7+dfsg-2ubuntu2.1+esm3
zabbixzabbix>= 0 < 1:3.0.12+dfsg-1ubuntu0.1~esm31:3.0.12+dfsg-1ubuntu0.1~esm3
zabbixzabbix>= 0 < 1:4.0.17+dfsg-1ubuntu0.1~esm11:4.0.17+dfsg-1ubuntu0.1~esm1
zabbixzabbix2.4.0 – 2.4.8

CVSS provenance

nvdv3.07.0HIGHCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vendor_ubuntu9.8CRITICAL
vendor_debian7.0HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.