CVE-2024-22123
12.08.2024, 13:38
Setting SMS media allows to set GSM modem file. Later this file is used as Linux device. But due everything is a file for Linux, it is possible to set another file, e.g. log file and zabbix_server will try to communicate with it as modem. As a result, log file will be broken with AT commands and small part for log file content will be leaked to UI.
Vendor | Product | Version |
---|---|---|
zabbix | zabbix | 5.0.0 ≤ 𝑥 ≤ 5.0.42 |
zabbix | zabbix | 6.0.0 ≤ 𝑥 ≤ 6.0.30 |
zabbix | zabbix | 6.4.0 ≤ 𝑥 ≤ 6.4.15 |
zabbix | zabbix | 7.0.0:alpha1 |
zabbix | zabbix | 7.0.0:alpha2 |
zabbix | zabbix | 7.0.0:alpha3 |
zabbix | zabbix | 7.0.0:alpha4 |
zabbix | zabbix | 7.0.0:alpha5 |
zabbix | zabbix | 7.0.0:alpha6 |
zabbix | zabbix | 7.0.0:alpha7 |
zabbix | zabbix | 7.0.0:alpha8 |
zabbix | zabbix | 7.0.0:alpha9 |
zabbix | zabbix | 7.0.0:beta1 |
zabbix | zabbix | 7.0.0:beta2 |
zabbix | zabbix | 7.0.0:beta3 |
zabbix | zabbix | 7.0.0:rc1 |
zabbix | zabbix | 7.0.0:rc2 |
𝑥
= Vulnerable software versions

Debian Releases