9.1

CVE-2024-22122

AT(GSM) Command Injection

Zabbix allows to configure SMS notifications. AT command injection occurs on "Zabbix Server" because there is no validation of "Number" field on Web nor on Zabbix server side. Attacker can run test of SMS providing specially crafted phone number and execute additional AT commands on modem.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zabbix ≫ Zabbix Version >= 5.0.0 <= 5.0.42
Zabbix ≫ Zabbix Version >= 6.0.0 <= 6.0.30
Zabbix ≫ Zabbix Version >= 6.4.0 <= 6.4.15
Zabbix ≫ Zabbix Version 7.0.0 Update alpha1
Zabbix ≫ Zabbix Version 7.0.0 Update alpha2
Zabbix ≫ Zabbix Version 7.0.0 Update alpha3
Zabbix ≫ Zabbix Version 7.0.0 Update alpha4
Zabbix ≫ Zabbix Version 7.0.0 Update alpha5
Zabbix ≫ Zabbix Version 7.0.0 Update alpha6
Zabbix ≫ Zabbix Version 7.0.0 Update alpha7
Zabbix ≫ Zabbix Version 7.0.0 Update alpha8
Zabbix ≫ Zabbix Version 7.0.0 Update alpha9
Zabbix ≫ Zabbix Version 7.0.0 Update beta1
Zabbix ≫ Zabbix Version 7.0.0 Update beta2
Zabbix ≫ Zabbix Version 7.0.0 Update beta3
Zabbix ≫ Zabbix Version 7.0.0 Update rc1
Zabbix ≫ Zabbix Version 7.0.0 Update rc2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.61% 0.727
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.1 2.3 6
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
security@zabbix.com 3 1.3 1.4
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:L/A:N
CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')

The product constructs all or part of a command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended command when it is sent to a downstream component.

https://support.zabbix.com/browse/ZBX-25012
Vendor Advisory
https://lists.debian.org/debian-lts-announce/2024/10/msg00000.html