CVE-2024-22120

EUVD-2024-19716
Zabbix server can perform command execution for configured scripts. After command is executed, audit entry is added to "Audit Log". Due to "clientip" field is not sanitized, it is possible to injection SQL into "clientip" and exploit time based blind SQL injection.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.1 CRITICAL
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
ZabbixCNA
9.1 CRITICAL
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 99%
Affected Products (NVD)
VendorProductVersion
zabbixzabbix
6.0.0 ≤
𝑥
< 6.0.28
zabbixzabbix
6.4.0 ≤
𝑥
< 6.4.13
zabbixzabbix
7.0.0:alpha1
zabbixzabbix
7.0.0:alpha2
zabbixzabbix
7.0.0:alpha3
zabbixzabbix
7.0.0:alpha4
zabbixzabbix
7.0.0:alpha5
zabbixzabbix
7.0.0:alpha6
zabbixzabbix
7.0.0:alpha7
zabbixzabbix
7.0.0:alpha8
zabbixzabbix
7.0.0:alpha9
zabbixzabbix
7.0.0:beta1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
zabbix
bookworm
vulnerable
bullseye
1:5.0.8+dfsg-1
not-affected
bullseye (security)
1:5.0.46+dfsg-1+deb11u1
fixed
buster
not-affected
sid
1:7.0.10+dfsg-2
fixed
trixie
1:7.0.10+dfsg-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
zabbix
bionic
needs-triage
focal
needs-triage
jammy
needs-triage
mantic
ignored
noble
dne
oracular
ignored
plucky
needs-triage
questing
needs-triage
trusty
needs-triage
xenial
needs-triage