Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2014-1682


The API in Zabbix before 1.8.20rc1, 2.0.x before 2.0.11rc1, and 2.2.x before 2.2.2rc1 allows remote authenticated users to spoof arbitrary users via the user name in a user.login request.


Published

2014-05-08T14:29:14.220

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv2: 4.0 (MEDIUM)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:N/I:P/A:N

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: NONE
  • Integrity Impact: PARTIAL
  • Availability Impact: NONE
Exploitability Score

8.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-287

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application zabbix zabbix ≤ 1.8.19 Yes
Application zabbix zabbix 1.8 Yes
Application zabbix zabbix 1.8.1 Yes
Application zabbix zabbix 1.8.2 Yes
Application zabbix zabbix 1.8.3 Yes
Application zabbix zabbix 1.8.3 Yes
Application zabbix zabbix 1.8.3 Yes
Application zabbix zabbix 1.8.15 Yes
Application zabbix zabbix 1.8.16 Yes
Application zabbix zabbix 1.8.18 Yes
Application zabbix zabbix 2.0.0 Yes
Application zabbix zabbix 2.0.0 Yes
Application zabbix zabbix 2.0.0 Yes
Application zabbix zabbix 2.0.0 Yes
Application zabbix zabbix 2.0.0 Yes
Application zabbix zabbix 2.0.0 Yes
Application zabbix zabbix 2.0.0 Yes
Application zabbix zabbix 2.0.1 Yes
Application zabbix zabbix 2.0.1 Yes
Application zabbix zabbix 2.0.1 Yes
Application zabbix zabbix 2.0.2 Yes
Application zabbix zabbix 2.0.2 Yes
Application zabbix zabbix 2.0.2 Yes
Application zabbix zabbix 2.0.3 Yes
Application zabbix zabbix 2.0.3 Yes
Application zabbix zabbix 2.0.3 Yes
Application zabbix zabbix 2.0.4 Yes
Application zabbix zabbix 2.0.4 Yes
Application zabbix zabbix 2.0.5 Yes
Application zabbix zabbix 2.0.5 Yes
Application zabbix zabbix 2.0.6 Yes
Application zabbix zabbix 2.0.6 Yes
Application zabbix zabbix 2.0.7 Yes
Application zabbix zabbix 2.0.8 Yes
Application zabbix zabbix 2.0.8 Yes
Application zabbix zabbix 2.0.9 Yes
Application zabbix zabbix 2.0.9 Yes
Application zabbix zabbix 2.0.10 Yes
Application zabbix zabbix 2.2.0 Yes
Application zabbix zabbix 2.2.0 Yes
Application zabbix zabbix 2.2.0 Yes
Application zabbix zabbix 2.2.1 Yes
Application zabbix zabbix 2.2.1 Yes
Application zabbix zabbix 2.2.1 Yes
Operating System fedoraproject fedora 19 Yes
Operating System fedoraproject fedora 20 Yes

References