Zabbix allows to configure SMS notifications. AT command injection occurs on "Zabbix Server" because there is no validation of "Number" field on Web nor on Zabbix server side. Attacker can run test of SMS providing specially crafted phone number and execute additional AT commands on modem.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://support.zabbix.com/browse/ZBX-25012 |
History
Fri, 09 Aug 2024 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Fri, 09 Aug 2024 13:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
Fri, 09 Aug 2024 09:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Zabbix allows to configure SMS notifications. AT command injection occurs on "Zabbix Server" because there is no validation of "Number" field on Web nor on Zabbix server side. Attacker can run test of SMS providing specially crafted phone number and execute additional AT commands on modem. | |
Title | AT(GSM) Command Injection | |
Weaknesses | CWE-77 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: Zabbix
Published: 2024-08-09T08:46:21.444Z
Updated: 2024-08-09T14:47:01.476Z
Reserved: 2024-01-05T07:44:01.395Z
Link: CVE-2024-22122
Vulnrichment
Updated: 2024-08-09T14:46:55.706Z
NVD
Status : Awaiting Analysis
Published: 2024-08-12T13:38:16.310
Modified: 2024-08-12T13:41:36.517
Link: CVE-2024-22122
Redhat
No data.