Remote Code Execution Vulnerability in Zabbix by Zabbix SIA
CVE-2021-46088

7.2HIGH

Key Information:

Vendor

Zabbix

Status
Vendor
CVE Published:
27 January 2022

What is CVE-2021-46088?

Zabbix 4.0 LTS, 4.2, 4.4, and 5.0 LTS contain a vulnerability that allows users with 'Zabbix Admin' privileges to execute arbitrary shell scripts on the application server. This poses significant risks as it enables unauthorized access to critical system functions, potentially compromising the entire server environment. Users are urged to review their permissions and upgrade to patched versions to mitigate this risk.

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.