« Back to list

CVE-2013-1364

Status: ModifiedMedium (5)—

The user.login function in Zabbix before 1.8.16 and 2.x before 2.0.5rc1 allows remote attackers to override LDAP configuration via the cnf parameter.

CVSS

Exploitation probability (EPSS)

EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).

Affected technologies (1)

CWEs

References

Raw JSON (NVD)

Show
{
  "id": "CVE-2013-1364",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
          "authentication": "NONE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2013-12-14T17:21:45.537",
  "references": [
    {
      "url": "http://secunia.com/advisories/55824",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://security.gentoo.org/glsa/glsa-201311-15.xml",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/57471",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.zabbix.com/rn1.8.16.php",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.zabbix.com/rn2.0.5rc1.php",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://support.zabbix.com/browse/ZBX-6097",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/55824",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://security.gentoo.org/glsa/glsa-201311-15.xml",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/57471",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.zabbix.com/rn1.8.16.php",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.zabbix.com/rn2.0.5rc1.php",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://support.zabbix.com/browse/ZBX-6097",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-287"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The user.login function in Zabbix before 1.8.16 and 2.x before 2.0.5rc1 allows remote attackers to override LDAP configuration via the cnf parameter."
    },
    {
      "lang": "es",
      "value": "La función user.login en Zabbix anteriores a 1.8.16 y 2.x (anteriores a 2.0.5rc1) permite a atacantes remotos sobreescribir configuraciones LDAP a través del parámetro cnf."
    }
  ],
  "lastModified": "2026-06-16T23:51:17.073",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "790CFCE1-C950-4866-A3AA-90FF2BC4D6DB",
              "versionEndIncluding": "1.8.15"
            },
            {
              "criteria": "cpe:2.3:a:zabbix:zabbix:2.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A13691AD-76EE-461B-A5A8-C8433AC907CE"
            },
            {
              "criteria": "cpe:2.3:a:zabbix:zabbix:2.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D7F5CFFB-7492-4E87-8B85-2EB99CE2A9EB"
            },
            {
              "criteria": "cpe:2.3:a:zabbix:zabbix:2.0.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "29ACE6F0-E3B4-4B9D-A40A-47B66BA81FA0"
            },
            {
              "criteria": "cpe:2.3:a:zabbix:zabbix:2.0.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E538292A-0573-4F6E-8504-F86863AE1D04"
            },
            {
              "criteria": "cpe:2.3:a:zabbix:zabbix:2.0.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8213C387-7A54-4C86-AB6C-DF72AA17EFD6"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}