← back
CVE-2024-22122lowCWE-77

AT(GSM) Command Injection

8Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 3epss 1.6%
exploitation probability
1.6%top 25% of all CVEs
observed exploitation
nono source reports it
Zabbix allows to configure SMS notifications. AT command injection occurs on "Zabbix Server" because there is no validation of "Number" field on Web nor on Zabbix server side. Attacker can run test of SMS providing specially crafted phone number and execute additional AT commands on modem.
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:L/A:N
Affected products
Zabbix · Zabbix