Debian Zabbix vulnerabilities
114 known vulnerabilities affecting debian/zabbix.
Total CVEs
114
CISA KEV
1
actively exploited
Public exploits
18
Exploited in wild
2
Severity breakdown
CRITICAL16HIGH23MEDIUM41LOW34
Vulnerabilities
Page 1 of 6
CVE-2022-23134P1LOWCVSS 3.7KEVPoCfixed in zabbix 1:6.0.7+dfsg-2 (bookworm)2022
CVE-2022-23134 [LOW] CVE-2022-23134: zabbix - After the initial setup process, some steps of setup.php file are reachable not ...
After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step checks and potentially change the configuration of Zabbix Frontend.
Scope: local
bookworm: resolved (fixed in 1:6.0.7+dfsg-2)
bullseye: resolved
forky: resolved (fixed in 1:6.0.7+dfsg-2)
sid:
debian
CVE-2024-22120P1CRITICALCVSS 9.1ExploitedPoCfixed in zabbix 1:6.0.29+dfsg-1 (forky)2024
CVE-2024-22120 [CRITICAL] CVE-2024-22120: zabbix - Zabbix server can perform command execution for configured scripts. After comman...
Zabbix server can perform command execution for configured scripts. After command is executed, audit entry is added to "Audit Log". Due to "clientip" field is not sanitized, it is possible to injection SQL into "clientip" and exploit time based blind SQL injection.
Scope: local
bookworm: open
bullseye: resolved
forky: resolved (fixed in 1:6.0.29+dfsg-1)
sid: reso
debian
CVE-2024-42327P1CRITICALCVSS 9.9PoCfixed in zabbix 1:7.0.1+dfsg-1 (forky)2024
CVE-2024-42327 [CRITICAL] CVE-2024-42327: zabbix - A non-admin user account on the Zabbix frontend with the default User role, or w...
A non-admin user account on the Zabbix frontend with the default User role, or with any other role that gives API access can exploit this vulnerability. An SQLi exists in the CUser class in the addRelatedObjects function, this function is being called from the CUser.get function which is available for every user who has API access.
Scope: local
bookworm: open
bul
debian
CVE-2016-10134P2CRITICALCVSS 9.8PoCfixed in zabbix 1:3.0.4+dfsg-1 (bookworm)2016
CVE-2016-10134 [CRITICAL] CVE-2016-10134: zabbix - SQL injection vulnerability in Zabbix before 2.2.14 and 3.0 before 3.0.4 allows ...
SQL injection vulnerability in Zabbix before 2.2.14 and 3.0 before 3.0.4 allows remote attackers to execute arbitrary SQL commands via the toggle_ids array parameter in latest.php.
Scope: local
bookworm: resolved (fixed in 1:3.0.4+dfsg-1)
bullseye: resolved (fixed in 1:3.0.4+dfsg-1)
forky: resolved (fixed in 1:3.0.4+dfsg-1)
sid: resolved (fixed in 1:3.0.4+dfsg-1)
debian
CVE-2013-5743P2CRITICALCVSS 9.8PoCfixed in zabbix 1:2.0.8+dfsg-2 (bookworm)2013
CVE-2013-5743 [CRITICAL] CVE-2013-5743: zabbix - Multiple SQL injection vulnerabilities in Zabbix 1.8.x before 1.8.18rc1, 2.0.x b...
Multiple SQL injection vulnerabilities in Zabbix 1.8.x before 1.8.18rc1, 2.0.x before 2.0.9rc1, and 2.1.x before 2.1.7.
Scope: local
bookworm: resolved (fixed in 1:2.0.8+dfsg-2)
bullseye: resolved (fixed in 1:2.0.8+dfsg-2)
forky: resolved (fixed in 1:2.0.8+dfsg-2)
sid: resolved (fixed in 1:2.0.8+dfsg-2)
trixie: resolved (fixed in 1:2.0.8+dfsg-2)
debian
CVE-2019-17382P2CRITICALCVSS 9.1PoCfixed in zabbix 1:5.0.0+dfsg-1 (bookworm)2019
CVE-2019-17382 [CRITICAL] CVE-2019-17382: zabbix - An issue was discovered in zabbix.php?action=dashboard.view&dashboardid=1 in Zab...
An issue was discovered in zabbix.php?action=dashboard.view&dashboardid=1 in Zabbix through 4.4. An attacker can bypass the login page and access the dashboard page, and then create a Dashboard, Report, Screen, or Map without any Username/Password (i.e., anonymously). All created elements (Dashboard/Report/Screen/Map) are accessible by other users and by an admin
debian
CVE-2016-4338P2HIGHCVSS 8.1PoCfixed in zabbix 1:3.0.3+dfsg-1 (bookworm)2016
CVE-2016-4338 [HIGH] CVE-2016-4338: zabbix - The mysql user parameter configuration script (userparameter_mysql.conf) in the ...
The mysql user parameter configuration script (userparameter_mysql.conf) in the agent in Zabbix before 2.0.18, 2.2.x before 2.2.13, and 3.0.x before 3.0.3, when used with a shell other than bash, allows context-dependent attackers to execute arbitrary code or SQL commands via the mysql.size parameter.
Scope: local
bookworm: resolved (fixed in 1:3.0.3+dfsg-1)
bullseye:
debian
CVE-2009-4502P2CRITICALCVSS 9.3PoCfixed in zabbix 1:1.8-1 (bookworm)2009
CVE-2009-4502 [CRITICAL] CVE-2009-4502: zabbix - The NET_TCP_LISTEN function in net.c in Zabbix Agent before 1.6.7, when running ...
The NET_TCP_LISTEN function in net.c in Zabbix Agent before 1.6.7, when running on FreeBSD or Solaris, allows remote attackers to bypass the EnableRemoteCommands setting and execute arbitrary commands via shell metacharacters in the argument to net.tcp.listen. NOTE: this attack is limited to attacks from trusted IP addresses.
Scope: local
bookworm: resolved (fixed
debian
CVE-2009-4498P2MEDIUMCVSS 6.8PoCfixed in zabbix 1:1.8-1 (bookworm)2009
CVE-2009-4498 [MEDIUM] CVE-2009-4498: zabbix - The node_process_command function in Zabbix Server before 1.8 allows remote atta...
The node_process_command function in Zabbix Server before 1.8 allows remote attackers to execute arbitrary commands via a crafted request.
Scope: local
bookworm: resolved (fixed in 1:1.8-1)
bullseye: resolved (fixed in 1:1.8-1)
forky: resolved (fixed in 1:1.8-1)
sid: resolved (fixed in 1:1.8-1)
trixie: resolved (fixed in 1:1.8-1)
debian
CVE-2020-15803P3MEDIUMCVSS 6.1PoCfixed in zabbix 1:5.0.2+dfsg-1 (bookworm)2020
CVE-2020-15803 [MEDIUM] CVE-2020-15803: zabbix - Zabbix before 3.0.32rc1, 4.x before 4.0.22rc1, 4.1.x through 4.4.x before 4.4.10...
Zabbix before 3.0.32rc1, 4.x before 4.0.22rc1, 4.1.x through 4.4.x before 4.4.10rc1, and 5.x before 5.0.2rc1 allows stored XSS in the URL Widget.
Scope: local
bookworm: resolved (fixed in 1:5.0.2+dfsg-1)
bullseye: resolved (fixed in 1:5.0.2+dfsg-1)
forky: resolved (fixed in 1:5.0.2+dfsg-1)
sid: resolved (fixed in 1:5.0.2+dfsg-1)
trixie: resolved (fixed in 1:5.0.2+d
debian
CVE-2024-36465P2LOWCVSS 8.6fixed in zabbix 1:7.0.9+dfsg-1 (forky)2024
CVE-2024-36465 [HIGH] CVE-2024-36465: zabbix - A low privilege (regular) Zabbix user with API access can use SQL injection vuln...
A low privilege (regular) Zabbix user with API access can use SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL commands via the groupBy parameter.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved (fixed in 1:7.0.9+dfsg-1)
sid: resolved (fixed in 1:7.0.9+dfsg-1)
trixie: resolved (fixed in 1:7.0.9+dfsg-1)
debian
CVE-2012-3435P3HIGHCVSS 7.5PoCfixed in zabbix 1:2.0.2+dfsg-1 (bookworm)2012
CVE-2012-3435 [HIGH] CVE-2012-3435: zabbix - SQL injection vulnerability in frontends/php/popup_bitem.php in Zabbix 1.8.15rc1...
SQL injection vulnerability in frontends/php/popup_bitem.php in Zabbix 1.8.15rc1 and earlier, and 2.x before 2.0.2rc1, allows remote attackers to execute arbitrary SQL commands via the itemid parameter.
Scope: local
bookworm: resolved (fixed in 1:2.0.2+dfsg-1)
bullseye: resolved (fixed in 1:2.0.2+dfsg-1)
forky: resolved (fixed in 1:2.0.2+dfsg-1)
sid: resolved (fixed in
debian
CVE-2011-4674P3HIGHCVSS 7.5PoCfixed in zabbix 1:1.8.9-1 (bookworm)2011
CVE-2011-4674 [HIGH] CVE-2011-4674: zabbix - SQL injection vulnerability in popup.php in Zabbix 1.8.3 and 1.8.4, and possibly...
SQL injection vulnerability in popup.php in Zabbix 1.8.3 and 1.8.4, and possibly other versions before 1.8.9, allows remote attackers to execute arbitrary SQL commands via the only_hostid parameter.
Scope: local
bookworm: resolved (fixed in 1:1.8.9-1)
bullseye: resolved (fixed in 1:1.8.9-1)
forky: resolved (fixed in 1:1.8.9-1)
sid: resolved (fixed in 1:1.8.9-1)
trixie:
debian
CVE-2009-4499P3HIGHCVSS 7.5PoCfixed in zabbix 1:1.8-1 (bookworm)2009
CVE-2009-4499 [HIGH] CVE-2009-4499: zabbix - SQL injection vulnerability in the get_history_lastid function in the nodewatche...
SQL injection vulnerability in the get_history_lastid function in the nodewatcher component in Zabbix Server before 1.6.8 allows remote attackers to execute arbitrary SQL commands via a crafted request, possibly related to the send_history_last_id function in zabbix_server/trapper/nodehistory.c.
Scope: local
bookworm: resolved (fixed in 1:1.8-1)
bullseye: resolved (fix
debian
CVE-2017-2824P2HIGHCVSS 8.1fixed in zabbix 1:3.0.7+dfsg-3 (bookworm)2017
CVE-2017-2824 [HIGH] CVE-2017-2824: zabbix - An exploitable code execution vulnerability exists in the trapper command functi...
An exploitable code execution vulnerability exists in the trapper command functionality of Zabbix Server 2.4.X. A specially crafted set of packets can cause a command injection resulting in remote code execution. An attacker can make requests from an active Zabbix Proxy to trigger this vulnerability.
Scope: local
bookworm: resolved (fixed in 1:3.0.7+dfsg-3)
bullseye: r
debian
CVE-2020-11800P2CRITICALCVSS 9.8fixed in zabbix 1:4.0.0+dfsg-1 (bookworm)2020
CVE-2020-11800 [CRITICAL] CVE-2020-11800: zabbix - Zabbix Server 2.2.x and 3.0.x before 3.0.31, and 3.2 allows remote attackers to ...
Zabbix Server 2.2.x and 3.0.x before 3.0.31, and 3.2 allows remote attackers to execute arbitrary code.
Scope: local
bookworm: resolved (fixed in 1:4.0.0+dfsg-1)
bullseye: resolved (fixed in 1:4.0.0+dfsg-1)
forky: resolved (fixed in 1:4.0.0+dfsg-1)
sid: resolved (fixed in 1:4.0.0+dfsg-1)
trixie: resolved (fixed in 1:4.0.0+dfsg-1)
debian
CVE-2006-6692P3MEDIUMCVSS 7.5PoCfixed in zabbix 1:1.1.2-4 (bookworm)2006
CVE-2006-6692 [HIGH] CVE-2006-6692: zabbix - Multiple format string vulnerabilities in zabbix before 20061006 allow attackers...
Multiple format string vulnerabilities in zabbix before 20061006 allow attackers to cause a denial of service (application crash) and possibly execute arbitrary code via format string specifiers in information that would be recorded in the system log using (1) zabbix_log or (2) zabbix_syslog.
Scope: local
bookworm: resolved (fixed in 1:1.1.2-4)
bullseye: resolved (fixe
debian
CVE-2023-32728P3MEDIUMCVSS 4.6fixed in zabbix 1:6.0.24+dfsg-1 (forky)2023
CVE-2023-32728 [MEDIUM] CVE-2023-32728: zabbix - The Zabbix Agent 2 item key smart.disk.get does not sanitize its parameters befo...
The Zabbix Agent 2 item key smart.disk.get does not sanitize its parameters before passing them to a shell command resulting possible vulnerability for remote code execution.
Scope: local
bookworm: open
bullseye: resolved
forky: resolved (fixed in 1:6.0.24+dfsg-1)
sid: resolved (fixed in 1:6.0.24+dfsg-1)
trixie: resolved (fixed in 1:6.0.24+dfsg-1)
debian
CVE-2024-22122P3LOWCVSS 3.0fixed in zabbix 1:5.0.44+dfsg-1+deb11u1 (bullseye)2024
CVE-2024-22122 [LOW] CVE-2024-22122: zabbix - Zabbix allows to configure SMS notifications. AT command injection occurs on "Za...
Zabbix allows to configure SMS notifications. AT command injection occurs on "Zabbix Server" because there is no validation of "Number" field on Web nor on Zabbix server side. Attacker can run test of SMS providing specially crafted phone number and execute additional AT commands on modem.
Scope: local
bookworm: open
bullseye: resolved (fixed in 1:5.0.44+dfsg-1+deb11u
debian
CVE-2022-43515P3MEDIUMCVSS 5.3fixed in zabbix 1:6.0.13+dfsg-1 (bookworm)2022
CVE-2022-43515 [MEDIUM] CVE-2022-43515: zabbix - Zabbix Frontend provides a feature that allows admins to maintain the installati...
Zabbix Frontend provides a feature that allows admins to maintain the installation and ensure that only certain IP addresses can access it. In this way, any user will not be able to access the Zabbix Frontend while it is being maintained and possible sensitive data will be prevented from being disclosed. An attacker can bypass this protection and access the instanc
debian
1 / 6Next →