CVE-2024-45700
published 2025-04-02CVE-2024-45700: Zabbix server is vulnerable to a DoS vulnerability due to uncontrolled resource exhaustion. An attacker can send specially crafted requests to the server…
PriorityP426medium6.5CVSS 3.1
AVAACLPRNUINSUCNINAH
EPSS
0.35%
27.3th percentile
Zabbix server is vulnerable to a DoS vulnerability due to uncontrolled resource exhaustion. An attacker can send specially crafted requests to the server, which will cause the server to allocate an excessive amount of memory and perform CPU-intensive decompression operations, ultimately leading to a service crash.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | zabbix | < zabbix 1:5.0.46+dfsg-1+deb11u1 (bullseye) | zabbix 1:5.0.46+dfsg-1+deb11u1 (bullseye) |
| zabbix | zabbix | >= 0 < 1:5.0.46+dfsg-1+deb11u1 | 1:5.0.46+dfsg-1+deb11u1 |
| zabbix | zabbix | >= 0 < 1:7.0.10+dfsg-1 | 1:7.0.10+dfsg-1 |
| zabbix | zabbix | >= 0 < 1:7.0.10+dfsg-1 | 1:7.0.10+dfsg-1 |
| zabbix | zabbix | >= 6.0.0 < 6.0.39 | 6.0.39 |
| zabbix | zabbix | 6.0.0 – 6.0.38 | — |
| zabbix | zabbix | >= 7.0.0 < 7.0.10 | 7.0.10 |
| zabbix | zabbix | 7.0.0 – 7.0.9 | — |
| zabbix | zabbix | >= 7.2.0 < 7.2.4 | 7.2.4 |
| zabbix | zabbix | 7.2.0 – 7.2.3 | — |
CVSS provenance
nvdv3.16.5MEDIUMCVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv4.06.0MEDIUMCVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
osv6.0MEDIUM
vendor_debian6.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2024-45700: zabbix - Zabbix server is vulnerable to a DoS vulnerability due to uncontrolled resource ...
vendor_debian·2024·CVSS 6.0
CVE-2024-45700 [MEDIUM] CVE-2024-45700: zabbix - Zabbix server is vulnerable to a DoS vulnerability due to uncontrolled resource ...
Zabbix server is vulnerable to a DoS vulnerability due to uncontrolled resource exhaustion. An attacker can send specially crafted requests to the server, which will cause the server to allocate an excessive amount of memory and perform CPU-intensive decompression operations, ultimately leading to a service crash.
Scope: local
bookworm: open
bullseye: resolved (fixed in 1:5.0.46+dfsg-1+deb11u1)
forky: resolved (fixed in 1:7.0.10+dfsg-1)
sid: resolved (fixed in 1:7.0.10+dfsg-1)
trixie: resolved (fixed in 1:7.0.10+dfsg-1)
OSV
CVE-2024-45700: Zabbix server is vulnerable to a DoS vulnerability due to uncontrolled resource exhaustion
osv·2025-04-02·CVSS 6.0
CVE-2024-45700 [MEDIUM] CVE-2024-45700: Zabbix server is vulnerable to a DoS vulnerability due to uncontrolled resource exhaustion
Zabbix server is vulnerable to a DoS vulnerability due to uncontrolled resource exhaustion. An attacker can send specially crafted requests to the server, which will cause the server to allocate an excessive amount of memory and perform CPU-intensive decompression operations, ultimately leading to a service crash.
GHSA
GHSA-8w8h-m7f2-m6c4: Zabbix server is vulnerable to a DoS vulnerability due to uncontrolled resource exhaustion
ghsa_unreviewed·2025-04-02
CVE-2024-45700 [MEDIUM] CWE-770 GHSA-8w8h-m7f2-m6c4: Zabbix server is vulnerable to a DoS vulnerability due to uncontrolled resource exhaustion
Zabbix server is vulnerable to a DoS vulnerability due to uncontrolled resource exhaustion. An attacker can send specially crafted requests to the server, which will cause the server to allocate an excessive amount of memory and perform CPU-intensive decompression operations, ultimately leading to a service crash.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-04-02
Published