CVE-2024-22122
LOWZabbix 5.0.0-5.0.41 - OS Command Injection via SMS Notification Number Field
Title source: llmDescription
Zabbix allows to configure SMS notifications. AT command injection occurs on "Zabbix Server" because there is no validation of "Number" field on Web nor on Zabbix server side. Attacker can run test of SMS providing specially crafted phone number and execute additional AT commands on modem.
References (2)
Core 2
Core References
Vendor Advisory
https://support.zabbix.com/browse/ZBX-25012
Scores
CVSS v3
3.0
EPSS
0.0161
EPSS Percentile
72.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:L/A:N
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-77
Status
published
Products (2)
zabbix/zabbix
7.0.0 alpha1 (14 CPE variants)
zabbix/zabbix
5.0.0 - 5.0.42
Published
Aug 12, 2024
Tracked Since
Feb 18, 2026