lists.debian.org
https://lists.debian.org/debian-lts-announce/2025/04/msg00027.html CVE-2024-45700
MEDIUM
DoS vulnerability due to uncontrolled resource exhaustion
Record summary
CVE-2024-45700 has a selected CVSS score of 6.0 (medium).
Description
Zabbix server is vulnerable to a DoS vulnerability due to uncontrolled resource exhaustion. An attacker can send specially crafted requests to the server, which will cause the server to allocate an excessive amount of memory and perform CPU-intensive decompression operations, ultimately leading to a service crash.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 2, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
ZabbixBrowse Zabbix / ZabbixDefault status: unaffected | CVE List | 6.0.0 to ≤ 6.0.38 | affected |
| 7.0.0 to ≤ 7.0.9 | affected | ||
| 7.2.0 to ≤ 7.2.3 | affected | ||
| 7.4.0alpha1 | unaffected |
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2024-45700 support.zabbix.com
https://support.zabbix.com/browse/ZBX-26253