First published: Tue Oct 01 2013(Updated: )
Zabbix 2.0.5 allows remote authenticated users to discover the LDAP bind password by leveraging management-console access and reading the ldap_bind_password value in the HTML source code.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zabbix Server | =2.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-5572 is considered a high severity vulnerability due to the potential exposure of sensitive LDAP bind passwords.
To fix CVE-2013-5572, upgrade to a later version of Zabbix that addresses this vulnerability.
CVE-2013-5572 affects systems running Zabbix version 2.0.5 with remote authenticated users.
CVE-2013-5572 allows an attacker to discover the LDAP bind password through management-console access.
CVE-2013-5572 was published on September 3, 2013.