cbcvebase.
CVE-2020-11800
published 2020-10-07

CVE-2020-11800: Zabbix Server 2.2.x and 3.0.x before 3.0.31, and 3.2 allows remote attackers to execute arbitrary code.

critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
Zabbix Server 2.2.x and 3.0.x before 3.0.31, and 3.2 allows remote attackers to execute arbitrary code.

Affected

15 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianzabbix< zabbix 1:4.0.0+dfsg-1 (bookworm)zabbix 1:4.0.0+dfsg-1 (bookworm)
opensusebackports_sle
opensuseleap
opensuseleap
zabbixzabbix
zabbixzabbix>= 0 < 1:4.0.0+dfsg-11:4.0.0+dfsg-1
zabbixzabbix>= 0 < 1:4.0.0+dfsg-11:4.0.0+dfsg-1
zabbixzabbix>= 0 < 1:4.0.0+dfsg-11:4.0.0+dfsg-1
zabbixzabbix>= 0 < 1:4.0.0+dfsg-11:4.0.0+dfsg-1
zabbixzabbix>= 0 < 1:2.2.2+dfsg-1ubuntu1+esm41:2.2.2+dfsg-1ubuntu1+esm4
zabbixzabbix>= 0 < 1:2.4.7+dfsg-2ubuntu2.1+esm31:2.4.7+dfsg-2ubuntu2.1+esm3
zabbixzabbix>= 0 < 1:3.0.12+dfsg-1ubuntu0.1~esm31:3.0.12+dfsg-1ubuntu0.1~esm3
zabbixzabbix>= 0 < 1:4.0.17+dfsg-1ubuntu0.1~esm11:4.0.17+dfsg-1ubuntu0.1~esm1
zabbixzabbix>= 2.2.0 < 3.0.313.0.31

CVSS provenance

nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL