First published: Sat Nov 30 2019(Updated: )
Zabbix before 5.0 represents passwords in the users table with unsalted MD5.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Zabbix Server | =2.0.8 | |
Zabbix Server | =4.4.0-alpha2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2013-7484.
The severity of CVE-2013-7484 is high with a CVSS score of 7.5.
The affected software versions are Zabbix 2.0.8 and Zabbix 4.4.0-alpha2.
Passwords in the users table in Zabbix before version 5.0 are represented with unsalted MD5 hashes.
Yes, you can find more information about CVE-2013-7484 in the following references: [link 1](https://lists.debian.org/debian-lts-announce/2023/08/msg00027.html), [link 2](https://support.zabbix.com/browse/ZBX-16551), [link 3](https://support.zabbix.com/browse/ZBXNEXT-1898).