CVE-2013-7484: Weak Encryption
Published Nov 30, 2019
·Updated
Zabbix before 5.0 represents passwords in the users table with unsalted MD5.
Affected Software
2 affected components
Zabbix Zabbix=2.0.8
Zabbix Zabbix=4.4.0-alpha2
Event History
Nov 30, 2019
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2013-7484.
2
What is the severity of CVE-2013-7484?
The severity of CVE-2013-7484 is high with a CVSS score of 7.5.
3
What software versions are affected by CVE-2013-7484?
The affected software versions are Zabbix 2.0.8 and Zabbix 4.4.0-alpha2.
4
How are passwords represented in the users table in Zabbix before version 5.0?
Passwords in the users table in Zabbix before version 5.0 are represented with unsalted MD5 hashes.
5
Are there any references or additional information available for CVE-2013-7484?
Yes, you can find more information about CVE-2013-7484 in the following references: [link 1](https://lists.debian.org/debian-lts-announce/2023/08/msg00027.html), [link 2](https://support.zabbix.com/browse/ZBX-16551), [link 3](https://support.zabbix.com/browse/ZBXNEXT-1898).