CVE-2024-22123

EUVD-2024-19719
Setting SMS media allows to set GSM modem file. Later this file is used as Linux device. But due everything is a file for Linux, it is possible to set another file, e.g. log file and zabbix_server will try to communicate with it as modem. As a result, log file will be broken with AT commands and small part for log file content will be leaked to UI.
Code Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
2.7 LOW
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
ZabbixCNA
2.7 LOW
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 60%
Affected Products (NVD)
VendorProductVersion
zabbixzabbix
5.0.0 ≤
𝑥
≤ 5.0.42
zabbixzabbix
6.0.0 ≤
𝑥
≤ 6.0.30
zabbixzabbix
6.4.0 ≤
𝑥
≤ 6.4.15
zabbixzabbix
7.0.0:alpha1
zabbixzabbix
7.0.0:alpha2
zabbixzabbix
7.0.0:alpha3
zabbixzabbix
7.0.0:alpha4
zabbixzabbix
7.0.0:alpha5
zabbixzabbix
7.0.0:alpha6
zabbixzabbix
7.0.0:alpha7
zabbixzabbix
7.0.0:alpha8
zabbixzabbix
7.0.0:alpha9
zabbixzabbix
7.0.0:beta1
zabbixzabbix
7.0.0:beta2
zabbixzabbix
7.0.0:beta3
zabbixzabbix
7.0.0:rc1
zabbixzabbix
7.0.0:rc2
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
zabbix
bookworm
vulnerable
bullseye
vulnerable
bullseye (security)
1:5.0.46+dfsg-1+deb11u1
fixed
sid
1:7.0.10+dfsg-2
fixed
trixie
1:7.0.10+dfsg-2
fixed