CVE-2024-22122 - CERT CVE
ID CVE-2024-22122
Sažetak Zabbix allows to configure SMS notifications. AT command injection occurs on "Zabbix Server" because there is no validation of "Number" field on Web nor on Zabbix server side. Attacker can run test of SMS providing specially crafted phone number and execute additional AT commands on modem.
Reference
CVSS
Base: 3.0
Impact: 1.4
Exploitability:1.3
Pristup
VektorSloženostAutentikacija
NETWORK HIGH HIGH
Impact
PovjerljivostCjelovitostDostupnost
NONE LOW NONE
CVSS vektor CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:L/A:N
Zadnje važnije ažuriranje 10-12-2024 - 19:21
Objavljeno 12-08-2024 - 13:38