vulnerability

Debian: CVE-2024-22122: zabbix -- security update

Severity
3
CVSS
(AV:N/AC:M/Au:M/C:N/I:P/A:N)
Published
Aug 12, 2024
Added
Oct 7, 2024
Modified
Aug 15, 2025

Description

Zabbix allows to configure SMS notifications. AT command injection occurs on "Zabbix Server" because there is no validation of "Number" field on Web nor on Zabbix server side. Attacker can run test of SMS providing specially crafted phone number and execute additional AT commands on modem.

Solutions

debian-upgrade-zabbixno-fix-debian-deb-package
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.