Zabbix Vulnerabilities and Affected Products
Vulnerabilities associated with zabbix_server.
Products
Clear product- Zabbix68 vulnerabilities
- Frontend12 vulnerabilities
- Zabbix agent 2 (MSI packages)2 vulnerabilities
- Proxy, Server1 vulnerability
- Web Service Report Generation1 vulnerability
- Zabbix agent (MSI packages)1 vulnerability
- Zabbix Server1 vulnerability
- zabbix-agent21 vulnerability
- zabbix_server1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-22120CRITICAL | Time Based SQL Injection in Zabbix Server Audit LogZabbix server can perform command execution for configured scripts. After command is executed, audit entry is added to "Audit Log". Due to "clientip" field is not sanitized, it is possible to injection SQL into "clientip" and exploit time based blind SQL injection. | CVSS9.1v3.1 | EPSS76.6% | PoCs4 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |