Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2017-2824

An exploitable code execution vulnerability exists in the trapper command functionality of Zabbix Server 2.4.X. A specially crafted set of packets can cause a command injection resulting in remote code execution. An attacker can make requests from an active Zabbix Proxy to trigger this vulnerability.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.735
EPSS Ranking 98.7%
CVSS Severity
CVSS v3 Score 8.1
CVSS v2 Score 6.8
Products affected by CVE-2017-2824
  • Zabbix » Zabbix » Version: 2.4.0
    cpe:2.3:a:zabbix:zabbix:2.4.0
  • Zabbix » Zabbix » Version: 2.4.1
    cpe:2.3:a:zabbix:zabbix:2.4.1
  • Zabbix » Zabbix » Version: 2.4.2
    cpe:2.3:a:zabbix:zabbix:2.4.2
  • Zabbix » Zabbix » Version: 2.4.3
    cpe:2.3:a:zabbix:zabbix:2.4.3
  • Zabbix » Zabbix » Version: 2.4.4
    cpe:2.3:a:zabbix:zabbix:2.4.4
  • Zabbix » Zabbix » Version: 2.4.5
    cpe:2.3:a:zabbix:zabbix:2.4.5
  • Zabbix » Zabbix » Version: 2.4.6
    cpe:2.3:a:zabbix:zabbix:2.4.6
  • Zabbix » Zabbix » Version: 2.4.7
    cpe:2.3:a:zabbix:zabbix:2.4.7
  • Zabbix » Zabbix » Version: 2.4.8
    cpe:2.3:a:zabbix:zabbix:2.4.8
  • Zabbix » Zabbix » Version: 2.4.9
    cpe:2.3:a:zabbix:zabbix:2.4.9


Contact Us

Shodan ® - All rights reserved