CVE-2023-26035 is a critical unauthenticated remote code execution vulnerability affecting ZoneMinder versions prior to 1.36.33 and 1.37.33. This flaw, stemming from missing authorization in the snapshot action, allows attackers to execute arbitrary commands on the server. With a CVSS score of 9.8, it presents a severe risk of complete compromise (confidentiality, integrity, and availability). While not currently on the KEV catalog, public exploit modules exist, including a Metasploit module and Nuclei templates, indicating a high likelihood of exploitation. Community discussion and media coverage are currently low, but the availability of exploit code warrants immediate patching.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.36.33CPE matchmatch criteria | cpe:2.3:a:zoneminder:zoneminder:*:*:*:*:*:*:*:* | ||
>= 1.37.00, < 1.37.33CPE matchmatch criteria | cpe:2.3:a:zoneminder:zoneminder:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.