CVE-2024-22120 is a critical time-based blind SQL injection vulnerability affecting Zabbix server versions. It stems from unsanitized input in the "clientip" field within audit log entries, allowing authenticated attackers to inject SQL commands. With a CVSS score of 8.8 (High) and an EPSS score of 0.92992, this flaw presents a significant risk, enabling full compromise of confidentiality, integrity, and availability. While not yet in CISA's KEV catalog, Nuclei templates exist for exploitation, and there's community discussion indicating potential real-world targeting, including alleged sales of Zabbix admin access.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.0.0, <= 6.0.27CPE match | cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:* | ||
>= 6.4.0, <= 6.4.12CPE match | cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:* | ||
>= 6.0.0, < 6.0.28CPE matchmatch criteria | cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:* | ||
>= 6.4.0, < 6.4.13CPE matchmatch criteria | cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:* | ||
7.0.0CPE matchmatch criteria | cpe:2.3:a:zabbix:zabbix:7.0.0:alpha1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.