CVE-2013-5572: Low severity zabbix server vulnerability
Published Oct 1, 2013
·Updated
Zabbix 2.0.5 allows remote authenticated users to discover the LDAP bind password by leveraging management-console access and reading the ldapbindpassword value in the HTML source code.
Affected Software
1 affected component
Zabbix Zabbix=2.0.5
Event History
Oct 1, 2013
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2013-5572?
CVE-2013-5572 is considered a high severity vulnerability due to the potential exposure of sensitive LDAP bind passwords.
2
How do I fix CVE-2013-5572?
To fix CVE-2013-5572, upgrade to a later version of Zabbix that addresses this vulnerability.
3
Who is affected by CVE-2013-5572?
CVE-2013-5572 affects systems running Zabbix version 2.0.5 with remote authenticated users.
4
What type of attack does CVE-2013-5572 enable?
CVE-2013-5572 allows an attacker to discover the LDAP bind password through management-console access.
5
When was CVE-2013-5572 published?
CVE-2013-5572 was published on September 3, 2013.