cbcvebase.
CVE-2024-22123
published 2024-08-12

CVE-2024-22123: Setting SMS media allows to set GSM modem file. Later this file is used as Linux device. But due everything is a file for Linux, it is possible to set another…

PriorityP411low2.7CVSS 3.1
AVNACLPRHUINSUCNILAN
EPSS
0.57%
44.0th percentile
Setting SMS media allows to set GSM modem file. Later this file is used as Linux device. But due everything is a file for Linux, it is possible to set another file, e.g. log file and zabbix_server will try to communicate with it as modem. As a result, log file will be broken with AT commands and small part for log file content will be leaked to UI.

Affected

9 ranges
VendorProductVersion rangeFixed in
debianzabbix< zabbix 1:5.0.44+dfsg-1+deb11u1 (bullseye)zabbix 1:5.0.44+dfsg-1+deb11u1 (bullseye)
zabbixzabbix
zabbixzabbix>= 0 < 1:5.0.44+dfsg-1+deb11u11:5.0.44+dfsg-1+deb11u1
zabbixzabbix>= 0 < 1:7.0.0+dfsg-11:7.0.0+dfsg-1
zabbixzabbix>= 0 < 1:7.0.0+dfsg-11:7.0.0+dfsg-1
zabbixzabbix5.0.0 – 5.0.42
zabbixzabbix6.0.0 – 6.0.30
zabbixzabbix6.4.0 – 6.4.15
zabbixzabbix7.0.0alpha1 – 7.0.0rc2

CVSS provenance

nvdv3.12.7LOWCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N
osv2.7LOW
vendor_debian2.7LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.