PT-2024-3624 · Zabbix+4 · Zabbix Server+4

Maris Melnikovs

·

Published

2024-05-17

·

Updated

2026-02-13

·

CVE-2024-22120

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Zabbix server versions 6.0.0 through 6.0.27 Zabbix server versions 6.4.0 through 6.4.12 Zabbix server versions 7.0.0alpha1 through 7.0.0beta1
Description: The Zabbix server is vulnerable to a time-based SQL injection attack due to the "clientip" field not being sanitized. This allows an attacker to inject SQL into the "clientip" field and exploit the vulnerability. The attack can lead to privilege escalation from user to admin and, in some cases, remote code execution. The vulnerability is related to the execution of configured scripts and the addition of audit entries to the "Audit Log".
Recommendations: For Zabbix server versions 6.0.0 through 6.0.27, update to version 6.0.28rc1 or later. For Zabbix server versions 6.4.0 through 6.4.12, update to version 6.4.13rc1 or later. For Zabbix server versions 7.0.0alpha1 through 7.0.0beta1, update to version 7.0.0beta2 or later. As a temporary workaround, consider disabling the execution of configured scripts until a patch is available. Restrict access to the "Audit Log" to minimize the risk of exploitation. Avoid using the "clientip" field in the affected API endpoint until the issue is resolved.

Exploit

Fix

RCE

Weakness Enumeration

Related Identifiers

ALT-PU-2024-11571
ALT-PU-2024-11575
ALT-PU-2024-12059
ALT-PU-2024-15832
BDU:2024-03942
CVE-2024-22120

Affected Products

Alt Linux
Astra Linux
Debian
Red Os
Zabbix Server