Vulnerability Description
Zabbix allows to configure SMS notifications. AT command injection occurs on "Zabbix Server" because there is no validation of "Number" field on Web nor on Zabbix server side. Attacker can run test of SMS providing specially crafted phone number and execute additional AT commands on modem.
CVSS Score
LOW
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Zabbix | Zabbix | >= 5.0.0, <= 5.0.42 |
Related Weaknesses (CWE)
References
- https://support.zabbix.com/browse/ZBX-25012Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2024/10/msg00000.html
FAQ
What is CVE-2024-22122?
CVE-2024-22122 is a vulnerability with a CVSS score of 3.0 (LOW). Zabbix allows to configure SMS notifications. AT command injection occurs on "Zabbix Server" because there is no validation of "Number" field on Web nor on Zabbix server side. Attacker can run test of...
How severe is CVE-2024-22122?
CVE-2024-22122 has been rated LOW with a CVSS base score of 3.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-22122?
Check the references section above for vendor advisories and patch information. Affected products include: Zabbix Zabbix.