PT-2024-6098 · Zabbix+4 · Zabbix+4

Maksim Tiukov

+1

·

Published

2024-08-09

·

Updated

2024-12-10

·

CVE-2024-22122

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Zabbix versions 5.0.0 through 7.0.0rc2
Description The issue is related to the configuration of SMS notifications in Zabbix, where an AT command injection occurs due to the lack of validation of the Number field. This allows an attacker to execute additional AT commands on the modem by providing a specially crafted phone number during an SMS test. The exploitation of this issue may enable a remote attacker to execute additional AT commands on the modem.
Recommendations For Zabbix versions 5.0.0 through 7.0.0rc2, update to the latest version to prevent remote attacks. As a temporary workaround, consider restricting access to the SMS notification feature until a patch is available. Avoid using the Number field in the SMS notification configuration until the issue is resolved.

Fix

Command Injection

Weakness Enumeration

Related Identifiers

ALT-PU-2024-11571
ALT-PU-2024-11575
ALT-PU-2024-15832
BDU:2024-07007
CVE-2024-22122
DLA-3909-1

Affected Products

Alt Linux
Astra Linux
Debian
Red Os
Zabbix