Input validation error - CVE-2014-1685
Published: May 8, 2014 / Updated: August 4, 2020
Vulnerability identifier: #VU33853
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2014-1685
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote #AU# to manipulate or delete data.
The Frontend in Zabbix before 1.8.20rc2, 2.0.x before 2.0.11rc2, and 2.2.x before 2.2.2rc1 allows remote "Zabbix Admin" users to modify the media of arbitrary users via unspecified vectors.
Affected software
zabbix (Alpine package)
net-snmp (Alpine package)
zabbix
zabbix20
Fedora
net-snmp (Alpine package)
zabbix
zabbix20
Fedora
How to mitigate CVE-2014-1685
Install update from vendor's website.
zabbix (Alpine package) - addressed in versions 1.8.20-r0, 2.0.11-r0
net-snmp (Alpine package) - update to 5.7.1-r4
zabbix - update to 1.8.20-1.el6
zabbix20 - addressed in versions 2.0.11-1.el5, 2.0.11-1.el6
net-snmp (Alpine package) - update to 5.7.1-r4
zabbix - update to 1.8.20-1.el6
zabbix20 - addressed in versions 2.0.11-1.el5, 2.0.11-1.el6