RULE(RULE ID:333423)

Rule General Information
Release Date: 2021-04-09
Rule Name: Zabbix Remote Code Execution Vulnerability (CVE-2020-11800)
Severity:
CVE ID:
Rule Protection Details
Description: Zabbix Server 2.2.x and 3.0.x before 3.0.31, and 3.2 allows remote attackers to execute arbitrary code.
Impact: An attacker can execute arbitrary code via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, Others
Reference: http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00007.html
https://lists.debian.org/debian-lts-announce/2020/11/msg00039.html
https://support.zabbix.com/browse/DEV-1538
https://support.zabbix.com/browse/ZBX-17600
Solutions
The vendor has released upgrade patches to fix vulnerabilities, please visit:
https://support.zabbix.com/browse/ZBX-17600