CyberzSOC

Publication detail
← Back to advisories & guidance

2024-082: Zabbix Server Critical Arbitrary Code Execution Vulnerability ↗ source

August 16, 2024 CERT-EU Advisory

Summary

The flaw, identified in the Ping script execution within the Monitoring Hosts section, can compromise the entire infrastructure. CVE-2024-22116 is a code injection vulnerability (CWE-94) where improper control over script parameters allows arbitrary code execution via the Ping script in the Monitoring Hosts section CERT-EU strongly recommends upgrading to Zabbix versions 6.4.16rc1 or 7.0.0rc3 immediately, as no workarounds are available.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2024-22116 9.9 Critical Zabbix Zabbix An administrator with restricted permissions can exploit the script execution functionality within the Monitoring Hosts section. The lack of default …

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.