← Back

CVE-2024-22123

nvd nist
Published: Aug 12, 2024Modified: Jun 17, 2026

JSON object

Loading...
2.7
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
Exploitability: 1.2 / Impact: 1.4
Source: NVD

Description

Setting SMS media allows to set GSM modem file. Later this file is used as Linux device. But due everything is a file for Linux, it is possible to set another file, e.g. log file and zabbix_server will try to communicate with it as modem. As a result, log file will be broken with AT commands and small part for log file content will be leaked to UI.

Affected (17)

Products: Zabbix: Zabbix
1 product
Zabbix
Configuration A
17 vulnerable
Vulnerable SoftwareAffected Versions
Zabbix
From 5.0.0 to 5.0.42
From 6.0.0 to 6.0.30
From 6.4.0 to 6.4.15
Version 7.0.0 alpha1
Version 7.0.0 alpha2
Version 7.0.0 alpha3
Version 7.0.0 alpha4
Version 7.0.0 alpha5
Version 7.0.0 alpha6
Version 7.0.0 alpha7
Version 7.0.0 alpha8
Version 7.0.0 alpha9
Version 7.0.0 beta1
Version 7.0.0 beta2
Version 7.0.0 beta3
Version 7.0.0 rc1
Version 7.0.0 rc2

References (2)

Source: security@zabbix.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108

Timeline

No history available yet.