Low severity3.7NVD Advisory· Published Apr 9, 2018· Updated Jun 17, 2026
CVE-2017-2826
CVE-2017-2826
Description
An information disclosure vulnerability exists in the iConfig proxy request of Zabbix server 2.4.X. A specially crafted iConfig proxy request can cause the Zabbix server to send the configuration information of any Zabbix proxy, resulting in information disclosure. An attacker can make requests from an active Zabbix proxy to trigger this vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
25cpe:2.3:a:zabbix:zabbix:2.4.0:*:*:*:*:*:*:*+ 22 more
- cpe:2.3:a:zabbix:zabbix:2.4.0:*:*:*:*:*:*:*
- cpe:2.3:a:zabbix:zabbix:2.4.0:rc1:*:*:*:*:*:*
- cpe:2.3:a:zabbix:zabbix:2.4.0:rc2:*:*:*:*:*:*
- cpe:2.3:a:zabbix:zabbix:2.4.0:rc3:*:*:*:*:*:*
- cpe:2.3:a:zabbix:zabbix:2.4.1:*:*:*:*:*:*:*
- cpe:2.3:a:zabbix:zabbix:2.4.1:rc1:*:*:*:*:*:*
- cpe:2.3:a:zabbix:zabbix:2.4.1:rc2:*:*:*:*:*:*
- cpe:2.3:a:zabbix:zabbix:2.4.2:*:*:*:*:*:*:*
- cpe:2.3:a:zabbix:zabbix:2.4.2:rc1:*:*:*:*:*:*
- cpe:2.3:a:zabbix:zabbix:2.4.3:*:*:*:*:*:*:*
- cpe:2.3:a:zabbix:zabbix:2.4.3:rc1:*:*:*:*:*:*
- cpe:2.3:a:zabbix:zabbix:2.4.4:*:*:*:*:*:*:*
- cpe:2.3:a:zabbix:zabbix:2.4.4:rc1:*:*:*:*:*:*
- cpe:2.3:a:zabbix:zabbix:2.4.5:*:*:*:*:*:*:*
- cpe:2.3:a:zabbix:zabbix:2.4.5:rc1:*:*:*:*:*:*
- cpe:2.3:a:zabbix:zabbix:2.4.6:*:*:*:*:*:*:*
- cpe:2.3:a:zabbix:zabbix:2.4.6:rc1:*:*:*:*:*:*
- cpe:2.3:a:zabbix:zabbix:2.4.7:*:*:*:*:*:*:*
- cpe:2.3:a:zabbix:zabbix:2.4.7:rc1:*:*:*:*:*:*
- cpe:2.3:a:zabbix:zabbix:2.4.8:*:*:*:*:*:*:*
- cpe:2.3:a:zabbix:zabbix:2.4.8:rc1:*:*:*:*:*:*
- cpe:2.3:a:zabbix:zabbix:2.4.9:*:*:*:*:*:*:*
- cpe:2.3:a:zabbix:zabbix:2.4.9:rc1:*:*:*:*:*:*
- Talos/Zabbixv5Range: Zabbix Server 2.4.8.r1
Patches
Vulnerability mechanics
References
2- talosintelligence.com/vulnerability_reports/TALOS-2017-0327nvdExploitThird Party Advisory
- lists.debian.org/debian-lts-announce/2019/03/msg00010.htmlnvdMailing ListThird Party Advisory
News mentions
0No linked articles in our index yet.