Language:
https://blog.talosintelligence.com/2017/04/zabbix-multiple-vulns.html
https://www.talosintelligence.com/reports/TALOS-2017-0325/
https://www.talosintelligence.com/reports/TALOS-2017-0326/
Severity: High
ID: 100615
File Name: zabbix_frontend_3_2_5.nasl
Version: 1.6
Type: remote
Family: CGI abuses
Published: 6/5/2017
Updated: 6/5/2024
Configuration: Enable paranoid mode, Enable thorough checks
Supported Sensors: Nessus
Enable CGI Scanning: true
Risk Factor: Medium
Score: 6.7
Risk Factor: Medium
Base Score: 6.8
Temporal Score: 5
Vector: CVSS2#AV:N/AC:M/Au:N/C:P/I:P/A:P
CVSS Score Source: CVE-2017-2825
Risk Factor: High
Base Score: 7
Temporal Score: 6.1
Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L
Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C
CPE: cpe:/a:zabbix:zabbix
Required KB Items: installed_sw/zabbix, Settings/ParanoidReport
Excluded KB Items: Settings/disable_cgi_scanning
Exploit Ease: No exploit is required
Patch Publication Date: 4/27/2017
Vulnerability Publication Date: 4/27/2017
CVE: CVE-2017-2824, CVE-2017-2825