Zabbix allows to configure SMS notifications. AT command injection occurs on "Zabbix Server" because there is no validation of "Number" field on Web nor on Zabbix server side. Attacker can run test of SMS providing specially crafted phone number and execute additional AT commands on modem.
History

Fri, 09 Aug 2024 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 09 Aug 2024 13:30:00 +0000


Fri, 09 Aug 2024 09:00:00 +0000

Type Values Removed Values Added
Description Zabbix allows to configure SMS notifications. AT command injection occurs on "Zabbix Server" because there is no validation of "Number" field on Web nor on Zabbix server side. Attacker can run test of SMS providing specially crafted phone number and execute additional AT commands on modem.
Title AT(GSM) Command Injection
Weaknesses CWE-77
References
Metrics cvssV3_1

{'score': 3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Zabbix

Published: 2024-08-09T08:46:21.444Z

Updated: 2024-08-09T14:47:01.476Z

Reserved: 2024-01-05T07:44:01.395Z

Link: CVE-2024-22122

cve-icon Vulnrichment

Updated: 2024-08-09T14:46:55.706Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2024-08-12T13:38:16.310

Modified: 2024-08-12T13:41:36.517

Link: CVE-2024-22122

cve-icon Redhat

No data.