Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2008-1353Zabbix vulnerability

7 documents7 sources
Severity
4.3MEDIUMNVD
EPSS
5.9%
top 9.42%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Affected products
Timeline
PublishedMar 17
Latest updateMay 1

Description

zabbix_agentd in ZABBIX 1.4.4 allows remote attackers to cause a denial of service (CPU and connection consumption) via multiple vfs.file.cksum commands with a special device node such as /dev/urandom or /dev/zero.

CVSS vector

AV:N/AC:M/C:N/I:N/A:PExploitability: 8.6 | Impact: 2.9

Affected Packages3 packages

debiandebian/zabbix< zabbix 1:1.4.5-1 (bookworm)
Debianzabbix/zabbix< 1:1.4.5-1+3
NVDzabbix/zabbix6 versions+5

🔴Vulnerability Details

2
GHSA
GHSA-2fgh-jwqp-hr3r: zabbix_agentd in ZABBIX 12022-05-01
OSV
CVE-2008-1353: zabbix_agentd in ZABBIX 12008-03-17

💥Exploits & PoCs

1
Exploit-DB
Zabbix 1.1x/1.4.x - File Checksum Request Denial of Service2008-03-13

📋Vendor Advisories

2
Debian
CVE-2008-1353: zabbix - zabbix_agentd in ZABBIX 1.4.4 allows remote attackers to cause a denial of servi...2008
Red Hat
zabbix file descriptor consumption by authorized hosts

💬Community

1
Bugzilla
CVE-2008-1353 zabbix file descriptor consumption by authorized hosts2008-03-17