APP: Zabbix Server Active Proxy Trapper Command Injection

This signature detects attempts to exploit a known vulnerability in Zabbix. Successful exploitation of this vulnerability could lead to arbitrary command execution in the context of the Zabbix process.

Extended Description

An exploitable code execution vulnerability exists in the trapper command functionality of Zabbix Server 2.4.X. A specially crafted set of packets can cause a command injection resulting in remote code execution. An attacker can make requests from an active Zabbix Proxy to trigger this vulnerability.

Affected Products

Zabbix zabbix

References

BugTraq: 98083

CVE: CVE-2017-2824

Short Name
APP:MISC:ZABBIX-PROXY-CI
Severity
Major
Recommended
True
Recommended Action
Drop
Category
APP
Keywords
Active CVE-2017-2824 Command Injection Proxy Server Trapper Zabbix bid:98083
Release Date
05/23/2017
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3337
Port
TCP/10051
False Positive
Unknown
Vendors

Zabbix

CVSS Score

6.8

Found a potential security threat?