CVE-2024-22122: AT(GSM) Command Injection
Zabbix allows to configure SMS notifications. AT command injection occurs on "Zabbix Server" because there is no validation of "Number" field on Web nor on Zabbix server side. Attacker can run test of SMS providing specially crafted phone number and execute additional AT commands on modem.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-22122?
CVE-2024-22122 has been classified as a critical vulnerability due to its potential for remote code execution via AT command injection.
How do I fix CVE-2024-22122?
To fix CVE-2024-22122, you should upgrade to version 7.0.0-beta3 or later, which includes patches for this vulnerability.
What versions of Zabbix are affected by CVE-2024-22122?
CVE-2024-22122 affects Zabbix versions from 5.0.0 to 6.4.15 and all alpha, beta, and rc versions of 7.0.0.
What are the potential impacts of CVE-2024-22122?
The impact of CVE-2024-22122 includes unauthorized access to system functions through command injection, potentially leading to complete system compromise.
Is it possible to exploit CVE-2024-22122 without authentication?
Yes, CVE-2024-22122 can be exploited without authentication by submitting specially crafted input in the SMS notification configuration.