Zabbix Arbitrary File Read
Vulnerability Description
Setting SMS media allows to set GSM modem file. Later this file is used as Linux device. But due everything is a file for Linux, it is possible to set another file, e.g. log file and zabbix_server will try to communicate with it as modem. As a result, log file will be broken with AT commands and small part for log file content will be leaked to UI.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-22123
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- Zabbix wants to thank -- who submitted this report in HackerOne bug bounty platform
References
More from Zabbix
View All →Affected Vendor
Zabbix
View all reports →