CVE-2013-1364: Medium severity Zabbix Zabbix vulnerability
Published Dec 14, 2013
·Updated
The user.login function in Zabbix before 1.8.16 and 2.x before 2.0.5rc1 allows remote attackers to override LDAP configuration via the cnf parameter.
Affected Software
6 affected components
Zabbix Zabbix<=1.8.15
Zabbix Zabbix=2.0.0
Zabbix Zabbix=2.0.1
Zabbix Zabbix=2.0.2
Zabbix Zabbix=2.0.3
Zabbix Zabbix=2.0.4
Event History
Dec 14, 2013
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-1364?
CVE-2013-1364 is considered a medium severity vulnerability due to its potential impact on LDAP configuration.
2
How do I fix CVE-2013-1364?
To fix CVE-2013-1364, upgrade Zabbix to version 1.8.16 or 2.0.5rc1 or later.
3
What versions of Zabbix are affected by CVE-2013-1364?
CVE-2013-1364 affects Zabbix versions prior to 1.8.16 and all 2.0.x versions before 2.0.5rc1.
4
What type of attack is possible with CVE-2013-1364?
CVE-2013-1364 allows remote attackers to override LDAP configurations, potentially leading to unauthorized access.
5
Is user authentication impacted by CVE-2013-1364?
Yes, CVE-2013-1364 can impact user authentication by allowing unauthorized LDAP configuration overrides.