CVE-2014-3005
XML external entity (XXE) vulnerability in Zabbix 1.8.x before 1.8.21rc1, 2.0.x before 2.0.13rc1, 2.2.x before 2.2.5rc1, and 2.3.x before 2.3.2 allows remote attackers to read arbitrary files or potentially execute arbitrary code via a crafted DTD in an…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (5.21%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
XML external entity (XXE) vulnerability in Zabbix 1.8.x before 1.8.21rc1, 2.0.x before 2.0.13rc1, 2.2.x before 2.2.5rc1, and 2.3.x before 2.3.2 allows remote attackers to read arbitrary files or potentially execute arbitrary code via a crafted DTD in an XML request.
- CVSS 3.0
- 9.8 CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 5.21% probability · 92th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-611
- Affected
- zabbix/zabbix · fedoraproject/fedora
- Source
- cve@mitre.org
References
- http://lists.fedoraproject.org/pipermail/package-announce/2014-June/134885.htmlThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2014-June/134909.htmlThird Party Advisory
- http://seclists.org/fulldisclosure/2014/Jun/87Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/68075Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=1110496Issue Tracking, Third Party Advisory
- https://support.zabbix.com/browse/ZBX-8151Exploit, Patch, Vendor Advisory
- https://web.archive.org/web/20140622034155/http://www.pnigos.com:80/?p=273Exploit, Third Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2014-June/134885.htmlThird Party Advisory
- http://lists.fedoraproject.org/pipermail/package-announce/2014-June/134909.htmlThird Party Advisory
- http://seclists.org/fulldisclosure/2014/Jun/87Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/68075Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=1110496Issue Tracking, Third Party Advisory
- https://support.zabbix.com/browse/ZBX-8151Exploit, Patch, Vendor Advisory
- https://web.archive.org/web/20140622034155/http://www.pnigos.com:80/?p=273Exploit, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.