Zabbix Server Vulnerability Lets Attacker Execute Arbitrary Code Via Ping Script

Post Reply
Shane1145
Posts: 1729
Joined: Wed Sep 25, 2024 2:31 pm

Zabbix Server Vulnerability Lets Attacker Execute Arbitrary Code Via Ping Script

Post by Shane1145 »

A critical security vulnerability, identified as CVE-2024-22116, has been patched in Zabbix, a popular monitoring solution. The vulnerability allowed an administrator with restricted permissions to execute arbitrary code via the Ping script in the Monitoring Hosts section, potentially compromising the infrastructure.

The vulnerability, which had a CVSS score of 9.9, was discovered by justonezero, a security researcher who submitted the report through the HackerOne bug bounty platform. Zabbix has acknowledged and thanked justonezero for their contribution to the platform’s security.



https://cybersecuritynews.com/zabbix-se ... erability/
Post Reply