CVE-2024-22121

EUVD-2024-19717
A non-admin user can change or remove important features within the Zabbix Agent application, thus impacting the integrity and availability of the application.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.1 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
ZabbixCNA
6.1 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
Base Score
CVSS 3.x
EPSS Score
Percentile: 8%
Affected Products (NVD)
VendorProductVersion
zabbixzabbix
5.0.0 ≤
𝑥
≤ 5.0.42
zabbixzabbix
6.0.0 ≤
𝑥
≤ 6.0.30
zabbixzabbix
6.4.0 ≤
𝑥
≤ 6.4.15
zabbixzabbix
7.0.0:alpha1
zabbixzabbix
7.0.0:alpha2
zabbixzabbix
7.0.0:alpha3
zabbixzabbix
7.0.0:alpha4
zabbixzabbix
7.0.0:alpha5
zabbixzabbix
7.0.0:alpha6
zabbixzabbix
7.0.0:alpha7
zabbixzabbix
7.0.0:alpha8
zabbixzabbix
7.0.0:alpha9
zabbixzabbix
7.0.0:beta1
zabbixzabbix
7.0.0:beta2
zabbixzabbix
7.0.0:beta3
zabbixzabbix
7.0.0:rc1
zabbixzabbix
7.0.0:rc2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
zabbix
bookworm
1:6.0.14+dfsg-1
fixed
bullseye
1:5.0.8+dfsg-1
fixed
bullseye (security)
1:5.0.46+dfsg-1+deb11u1
fixed
sid
1:7.0.10+dfsg-2
fixed
trixie
1:7.0.10+dfsg-2
fixed