PT-2024-6089 · Zabbix+2 · Zabbix Agent+3
Gee-Netics
+1
·
Published
2024-08-09
·
Updated
2024-12-10
·
CVE-2024-22121
CVSS v3.1
6.1
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
Zabbix Agent versions prior to 7.0.0rc2
Description
The issue is related to improper permission storage in the Zabbix Agent application. This can allow an attacker to elevate their privileges. A non-admin user can change or remove important features within the application, thus impacting its integrity and availability.
Recommendations
For versions prior to 7.0.0rc2, upgrade the affected components immediately to mitigate the risk. As a temporary workaround, consider restricting access to sensitive features within the Zabbix Agent application to prevent unauthorized changes.
Exploit
Fix
Improper Preservation of Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Red Os
Zabbix
Zabbix Agent