Impact
The Perl SNMP trap receiver script included with Zabbix fails to neutralize the ZBXTRAP record delimiter found inside trap content. This flaw allows an actor who can send SNMP traps to inject an additional record that targets a different host, thereby corrupting data integrity in the Zabbix monitoring system.
Affected Systems
All Zabbix installations that ship the zabbix_trap_receiver.pl script are affected. The vendor did not specify particular product versions, so any Zabbix instance relying on this script remains vulnerable until a fix is applied.
Risk and Exploitability
The CVSS score of 5.3 reflects moderate risk. EPSS data is unavailable and the vulnerability is not listed in the CISA KEV catalog, suggesting it is not widely exploited yet. Attack requires the ability to send SNMP traps to the Zabbix server, which can be achieved over the network by an attacker with network access to the trap interface. Successful exploitation results in loss of integrity of monitored data, without affecting confidentiality or availability.
OpenCVE Enrichment