CVE-2024-22123: Zabbix
Low severity, CVSS 2.7. EPSS: 0.6% chance of exploitation in the next 30 days.
Setting SMS media allows to set GSM modem file. Later this file is used as Linux device. But due everything is a file for Linux, it is possible to set another file, e.g. log file and zabbix_server will try to communicate with it as modem. As a result, log file will be broken with AT commands and small part for log file content will be leaked to UI.
Affected products
- Zabbix Zabbix: from 5.0.0, up to and including 5.0.42; from 6.0.0, up to and including 6.0.30; from 6.4.0, up to and including 6.4.15; version 7.0.0 only
Published 2024-08-12. Last modified 2026-06-17.