Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 6

Количество 6

ubuntu логотип

CVE-2024-22122

почти 2 года назад

Zabbix allows to configure SMS notifications. AT command injection occurs on "Zabbix Server" because there is no validation of "Number" field on Web nor on Zabbix server side. Attacker can run test of SMS providing specially crafted phone number and execute additional AT commands on modem.

CVSS3: 3
EPSS: Низкий
nvd логотип

CVE-2024-22122

почти 2 года назад

Zabbix allows to configure SMS notifications. AT command injection occurs on "Zabbix Server" because there is no validation of "Number" field on Web nor on Zabbix server side. Attacker can run test of SMS providing specially crafted phone number and execute additional AT commands on modem.

CVSS3: 3
EPSS: Низкий
debian логотип

CVE-2024-22122

почти 2 года назад

Zabbix allows to configure SMS notifications. AT command injection occ ...

CVSS3: 3
EPSS: Низкий
github логотип

GHSA-m34r-jrv8-mwmv

почти 2 года назад

Zabbix allows to configure SMS notifications. AT command injection occurs on "Zabbix Server" because there is no validation of "Number" field on Web nor on Zabbix server side. Attacker can run test of SMS providing specially crafted phone number and execute additional AT commands on modem.

CVSS3: 3
EPSS: Низкий
fstec логотип

BDU:2024-07007

почти 2 года назад

Уязвимость универсальной системы мониторинга Zabbix, связанная с неправильной нейтрализацией специальных элементов, используемых в команде, позволяющая нарушителю выполнить дополнительные AT-команды на модеме

CVSS3: 3
EPSS: Низкий
redos логотип

ROS-20240910-06

почти 2 года назад

Множественные уязвимости zabbix

CVSS3: 9.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2024-22122

Zabbix allows to configure SMS notifications. AT command injection occurs on "Zabbix Server" because there is no validation of "Number" field on Web nor on Zabbix server side. Attacker can run test of SMS providing specially crafted phone number and execute additional AT commands on modem.

CVSS3: 3
2%
Низкий
почти 2 года назад
nvd логотип
CVE-2024-22122

Zabbix allows to configure SMS notifications. AT command injection occurs on "Zabbix Server" because there is no validation of "Number" field on Web nor on Zabbix server side. Attacker can run test of SMS providing specially crafted phone number and execute additional AT commands on modem.

CVSS3: 3
2%
Низкий
почти 2 года назад
debian логотип
CVE-2024-22122

Zabbix allows to configure SMS notifications. AT command injection occ ...

CVSS3: 3
2%
Низкий
почти 2 года назад
github логотип
GHSA-m34r-jrv8-mwmv

Zabbix allows to configure SMS notifications. AT command injection occurs on "Zabbix Server" because there is no validation of "Number" field on Web nor on Zabbix server side. Attacker can run test of SMS providing specially crafted phone number and execute additional AT commands on modem.

CVSS3: 3
2%
Низкий
почти 2 года назад
fstec логотип
BDU:2024-07007

Уязвимость универсальной системы мониторинга Zabbix, связанная с неправильной нейтрализацией специальных элементов, используемых в команде, позволяющая нарушителю выполнить дополнительные AT-команды на модеме

CVSS3: 3
2%
Низкий
почти 2 года назад
redos логотип
ROS-20240910-06

Множественные уязвимости zabbix

CVSS3: 9.1
почти 2 года назад

Уязвимостей на страницу