CVE-2013-6824: Code Injection
Published Dec 19, 2013
·Updated
Zabbix before 1.8.19rc1, 2.0 before 2.0.10rc1, and 2.2 before 2.2.1rc1 allows remote Zabbix servers and proxies to execute arbitrary commands via a newline in a flexible user parameter.
Affected Software
3 affected components
Zabbix Zabbix<=1.8.18
Zabbix Zabbix=2.0.0
Zabbix Zabbix=2.2.0
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Dec 19, 2013
CVE Published
via MITRE·02:00 AM
Data Sourced
via MITRE·02:00 AM
Description
Data Sourced
via NVD·04:24 AM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-6824?
CVE-2013-6824 has been classified as a high severity vulnerability due to its ability to allow remote command execution.
2
How do I fix CVE-2013-6824?
To fix CVE-2013-6824, upgrade Zabbix to version 1.8.19rc1 or later, 2.0.10rc1 or later, or 2.2.1rc1 or later.
3
What systems are affected by CVE-2013-6824?
CVE-2013-6824 affects Zabbix versions prior to 1.8.19rc1, 2.0 before 2.0.10rc1, and 2.2 before 2.2.1rc1.
4
What are the potential consequences of CVE-2013-6824 exploitation?
Exploitation of CVE-2013-6824 can lead to unauthorized remote command execution on affected Zabbix servers.
5
Is there a workaround for CVE-2013-6824 if I cannot upgrade?
There are no official workarounds for CVE-2013-6824; upgrading to a secure version is the recommended solution.