Critical Flaw in Zabbix Server Allows Remote Code Execution Through Ping Script Exploit

A significant security flaw, designated as CVE-2024-22116, has been addressed in Zabbix, a widely-used monitoring platform. This flaw enabled administrators with limited permissions to run unauthorized code via the Ping script within the Monitoring Hosts section, potentially jeopardizing the entire infrastructure.

With a CVSS score of 9.9, this vulnerability was identified by the security researcher justonezero, who reported it through the HackerOne bug bounty program. Zabbix has publicly recognized and expressed gratitude to justonezero for their crucial contribution to enhancing the platform’s security.

According to Zabbix, “An administrator with restricted permissions could exploit the script execution feature in the Monitoring Hosts section. The absence of default parameter escaping allowed arbitrary code execution through the Ping script, thus compromising the system.”

The flaw impacted versions 6.4.0 to 6.4.15 and 7.0.0alpha1 to 7.0.0rc2. The issue has been remedied in versions 6.4.16rc1 and 7.0.0rc3, where patches have been applied to eliminate the vulnerability.

The vulnerability is classified under the Common Weakness Enumeration (CWE) as CWE-94, which involves improper control over the generation of code, commonly known as ‘Code Injection.’ Additionally, the Common Attack Pattern Enumeration and Classification (CAPEC) lists it as CAPEC-253, indicating a Remote Code Inclusion flaw.

Zabbix has confirmed that the vulnerability has been completely resolved, with no alternative workarounds available. Users are urged to upgrade to the latest patched versions to secure their monitoring systems.

Zabbix Server Vulnerability Technical Details:

  • Common Weakness Enumeration (CWE): CWE-94, Improper Control of Code Generation (‘Code Injection’)
  • Common Attack Pattern Enumeration and Classification (CAPEC): CAPEC-253, Remote Code Inclusion
  • Affected Versions: 6.4.0 – 6.4.15, 7.0.0alpha1 – 7.0.0rc2
  • Patched Versions: 6.4.16rc1, 7.0.0rc3

The latest release candidates, versions 6.4.16rc1 and 7.0.0rc3, have effectively addressed this issue. Users are strongly recommended to update their systems promptly to prevent any potential security breaches.

Zabbix Server users running versions 6.4.0 to 6.4.15 and 7.0.0alpha1 to 7.0.0rc2 should upgrade immediately to the corrected versions to safeguard their infrastructure. As there are no workarounds, this update is critical to maintaining a secure environment.

For further details on the vulnerability and corresponding patch, users should consult the official Zabbix release notes and security advisories.

More Articles & Posts