CVE-2024-22122

LOW

Zabbix 5.0.0-5.0.41 - OS Command Injection via SMS Notification Number Field

Title source: llm
STIX 2.1

Description

Zabbix allows to configure SMS notifications. AT command injection occurs on "Zabbix Server" because there is no validation of "Number" field on Web nor on Zabbix server side. Attacker can run test of SMS providing specially crafted phone number and execute additional AT commands on modem.

Scores

CVSS v3 3.0
EPSS 0.0161
EPSS Percentile 72.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:L/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-77
Status published
Products (2)
zabbix/zabbix 7.0.0 alpha1 (14 CPE variants)
zabbix/zabbix 5.0.0 - 5.0.42
Published Aug 12, 2024
Tracked Since Feb 18, 2026