Impact
The vulnerability allows an authenticated Zabbix administrator to crash the Zabbix server or proxy by creating specially crafted JavaScript scripts as preprocessing or script items. The flaw involves improper handling of JavaScript code, identified as CWE-248 (Unexpected End of File) and CWE-770 (Out‑of‑Resource Error). As a result, the server or proxy experiences a denial of service, disrupting monitoring operations.
Affected Systems
Zabbix servers and proxies that allow administrators to configure preprocessing or script items. No specific version details are provided, so any installation with this capability may be affected.
Risk and Exploitability
The CVSS score of 2.1 indicates low severity, and the EPSS score of less than 1% signals a very low probability of exploitation. The flaw is not listed in CISA KEV. The attack requires authenticated administrative privileges to add or modify scripts, so it requires local privileged access and cannot be performed from outside the system. Thus, while the impact is a service disruption, the overall risk is low unless administrator accounts are compromised or have excessive permissions.
OpenCVE Enrichment