← Back

CVE-2024-22122

nvd nist
Published: Aug 12, 2024Modified: Jun 17, 2026

JSON object

Loading...
9.1
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Exploitability: 2.3 / Impact: 6.0
Source: NVD

Description

Zabbix allows to configure SMS notifications. AT command injection occurs on "Zabbix Server" because there is no validation of "Number" field on Web nor on Zabbix server side. Attacker can run test of SMS providing specially crafted phone number and execute additional AT commands on modem.

Affected (17)

Products: Zabbix: Zabbix
1 product
Zabbix
Configuration A
17 vulnerable
Vulnerable SoftwareAffected Versions
Zabbix
From 5.0.0 to 5.0.42
From 6.0.0 to 6.0.30
From 6.4.0 to 6.4.15
Version 7.0.0 alpha1
Version 7.0.0 alpha2
Version 7.0.0 alpha3
Version 7.0.0 alpha4
Version 7.0.0 alpha5
Version 7.0.0 alpha6
Version 7.0.0 alpha7
Version 7.0.0 alpha8
Version 7.0.0 alpha9
Version 7.0.0 beta1
Version 7.0.0 beta2
Version 7.0.0 beta3
Version 7.0.0 rc1
Version 7.0.0 rc2

References (2)

Source: security@zabbix.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.