'; } else{ echo ''; } echo '
|
|
|||
Release Date:2025/9/15
Rule Name:CVE-2019-17382:Zabbix SIA Zabbix Authentication Bypass Vulnerability
Severity:critical
CVE ID:CVE-2019-17382
| Descripiton:
|
Zabbix SIA is an open-source monitoring system developed by the Latvian company Zabbix SIA. This system supports network monitoring, server monitoring, cloud monitoring, and application monitoring. Zabbix.php in Zabbix 4.4 and earlier versions? There is an authorization vulnerability in action=dashboard. view&dashboard=1. This vulnerability is caused by a lack of authentication measures or insufficient authentication strength in the network system or product. This rule supports to defend the A6: Vulnerable and Outdated Components of OWASP Top 10 - 2021.
Other reference:None
| Solution:
|
Update vendor patches.