vulnerability
Debian: CVE-2024-22122: zabbix -- security update
| Severity | CVSS | Published | Added | Modified |
|---|---|---|---|---|
| 3 | (AV:N/AC:M/Au:M/C:N/I:P/A:N) | Aug 12, 2024 | Oct 7, 2024 | Aug 15, 2025 |
Severity
3
CVSS
(AV:N/AC:M/Au:M/C:N/I:P/A:N)
Published
Aug 12, 2024
Added
Oct 7, 2024
Modified
Aug 15, 2025
Description
Zabbix allows to configure SMS notifications. AT command injection occurs on "Zabbix Server" because there is no validation of "Number" field on Web nor on Zabbix server side. Attacker can run test of SMS providing specially crafted phone number and execute additional AT commands on modem.
Solutions
debian-upgrade-zabbixno-fix-debian-deb-package
NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.