CVE-2024-22116
Severity CVSS v4.0:
Pending analysis
Type:
CWE-94
Code Injection
Publication date:
12/08/2024
Last modified:
03/11/2025
Description
An administrator with restricted permissions can exploit the script execution functionality within the Monitoring Hosts section. The lack of default escaping for script parameters enabled this user ability to execute arbitrary code via the Ping script, thereby compromising infrastructure.
Impact
Base Score 3.x
9.90
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:* | 6.4.9 (including) | 6.4.15 (including) |
| cpe:2.3:a:zabbix:zabbix:7.0.0:alpha1:*:*:*:*:*:* | ||
| cpe:2.3:a:zabbix:zabbix:7.0.0:alpha2:*:*:*:*:*:* | ||
| cpe:2.3:a:zabbix:zabbix:7.0.0:alpha3:*:*:*:*:*:* | ||
| cpe:2.3:a:zabbix:zabbix:7.0.0:alpha4:*:*:*:*:*:* | ||
| cpe:2.3:a:zabbix:zabbix:7.0.0:alpha5:*:*:*:*:*:* | ||
| cpe:2.3:a:zabbix:zabbix:7.0.0:alpha6:*:*:*:*:*:* | ||
| cpe:2.3:a:zabbix:zabbix:7.0.0:alpha7:*:*:*:*:*:* | ||
| cpe:2.3:a:zabbix:zabbix:7.0.0:alpha8:*:*:*:*:*:* | ||
| cpe:2.3:a:zabbix:zabbix:7.0.0:alpha9:*:*:*:*:*:* | ||
| cpe:2.3:a:zabbix:zabbix:7.0.0:beta1:*:*:*:*:*:* | ||
| cpe:2.3:a:zabbix:zabbix:7.0.0:beta2:*:*:*:*:*:* | ||
| cpe:2.3:a:zabbix:zabbix:7.0.0:beta3:*:*:*:*:*:* | ||
| cpe:2.3:a:zabbix:zabbix:7.0.0:rc1:*:*:*:*:*:* | ||
| cpe:2.3:a:zabbix:zabbix:7.0.0:rc2:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



