CVE-2023-26035
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
25/02/2023
Last modified:
14/11/2023
Description
ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 are vulnerable to Unauthenticated Remote Code Execution via Missing Authorization. There are no permissions check on the snapshot action, which expects an id to fetch an existing monitor but can be passed an object to create a new one instead. TriggerOn ends up calling shell_exec using the supplied Id. This issue is fixed in This issue is fixed in versions 1.36.33 and 1.37.33.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:zoneminder:zoneminder:*:*:*:*:*:*:*:* | 1.36.33 (excluding) | |
| cpe:2.3:a:zoneminder:zoneminder:*:*:*:*:*:*:*:* | 1.37.00 (including) | 1.37.33 (excluding) |
To consult the complete list of CPE names with products and versions, see this page



