PT-2024-6089 · Zabbix+2 · Zabbix Agent+3

Gee-Netics

+1

·

Published

2024-08-09

·

Updated

2024-12-10

·

CVE-2024-22121

CVSS v3.1

6.1

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions Zabbix Agent versions prior to 7.0.0rc2
Description The issue is related to improper permission storage in the Zabbix Agent application. This can allow an attacker to elevate their privileges. A non-admin user can change or remove important features within the application, thus impacting its integrity and availability.
Recommendations For versions prior to 7.0.0rc2, upgrade the affected components immediately to mitigate the risk. As a temporary workaround, consider restricting access to sensitive features within the Zabbix Agent application to prevent unauthorized changes.

Exploit

Fix

Improper Preservation of Permissions

Weakness Enumeration

Related Identifiers

ALT-PU-2024-11571
ALT-PU-2024-11575
ALT-PU-2024-15832
BDU:2024-06995
CVE-2024-22121

Affected Products

Alt Linux
Red Os
Zabbix
Zabbix Agent