CVE-2024-36468

LOW

Zabbix 7.0.0-7.0.3 - Stack-based Buffer Overflow in zbx_snmp_cache_handle_engineid

Title source: llm
STIX 2.1

Description

The reported vulnerability is a stack buffer overflow in the zbx_snmp_cache_handle_engineid function within the Zabbix server/proxy code. This issue occurs when copying data from session->securityEngineID to local_record.engineid without proper bounds checking.

References (1)

Core 1
Core References

Scores

CVSS v3 3.0
EPSS 0.0050
EPSS Percentile 38.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-121
Status published
Products (1)
zabbix/zabbix 7.0.0 - 7.0.3
Published Nov 27, 2024
Tracked Since Feb 18, 2026