// For flags

CVE-2024-42332

New line injection in Zabbix SNMP traps

Severity Score

3.7
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Track
*SSVC
Descriptions

The researcher is showing that due to the way the SNMP trap log is parsed, an attacker can craft an SNMP trap with additional lines of information and have forged data show in the Zabbix UI. This attack requires SNMP auth to be off and/or the attacker to know the community/auth details. The attack requires an SNMP item to be configured as text on the target host.

El investigador demuestra que, debido a la forma en que se analiza el registro de trampas SNMP, un atacante puede manipular una trampa SNMP con líneas de información adicionales y hacer que los datos falsificados se muestren en la interfaz de usuario de Zabbix. Este ataque requiere que la autenticación SNMP esté desactivada o que el atacante conozca los detalles de la comunidad o la autenticación. El ataque requiere que se configure un elemento SNMP como texto en el host de destino.

*Credits: Zabbix wants to thank chamal for submitting this report on the HackerOne bug bounty platform.
CVSS Scores
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:Track
Exploitation
None
Automatable
No
Tech. Impact
Partial
* Organization's Worst-case Scenario
Timeline
  • 2024-07-30 CVE Reserved
  • 2024-11-27 CVE Published
  • 2024-11-27 CVE Updated
  • 2024-11-28 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
CAPEC
  • CAPEC-93: Log Injection-Tampering-Forging
References (1)
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Zabbix
Search vendor "Zabbix"
Zabbix
Search vendor "Zabbix" for product "Zabbix"
>= 6.0.0 < 6.0.34
Search vendor "Zabbix" for product "Zabbix" and version " >= 6.0.0 < 6.0.34"
en
Affected
Zabbix
Search vendor "Zabbix"
Zabbix
Search vendor "Zabbix" for product "Zabbix"
>= 6.4.0 < 6.4.19
Search vendor "Zabbix" for product "Zabbix" and version " >= 6.4.0 < 6.4.19"
en
Affected
Zabbix
Search vendor "Zabbix"
Zabbix
Search vendor "Zabbix" for product "Zabbix"
>= 7.0.0 < 7.0.4
Search vendor "Zabbix" for product "Zabbix" and version " >= 7.0.0 < 7.0.4"
en
Affected