10

CVE-2022-22704

Exploit

The zabbix-agent2 package before 5.4.9-r1 for Alpine Linux sometimes allows privilege escalation to root because the design incorrectly expected that systemd would (in effect) determine part of the configuration.

Data is provided by the National Vulnerability Database (NVD)
ZabbixZabbix-agent2 Version < 5.4.9
   AlpinelinuxAlpine Linux Version-
ZabbixZabbix-agent2 Version5.4.9 Update-
   AlpinelinuxAlpine Linux Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.42% 0.61
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 10 10 10
AV:N/AC:L/Au:N/C:C/I:C/A:C
CWE-909 Missing Initialization of Resource

The product does not initialize a critical resource.