7.2
CVSSv3

CVE-2021-46088

Published: 27/01/2022 Updated: 02/02/2022
CVSS v2 Base Score: 6.5 | Impact Score: 6.4 | Exploitability Score: 8
CVSS v3 Base Score: 7.2 | Impact Score: 5.9 | Exploitability Score: 1.2
VMScore: 578
Vector: AV:N/AC:L/Au:S/C:P/I:P/A:P

Vulnerability Summary

Zabbix 4.0 LTS, 4.2, 4.4, and 5.0 LTS is vulnerable to Remote Code Execution (RCE). Any user with the "Zabbix Admin" role is able to run custom shell script on the application server in the context of the application user.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

zabbix zabbix

Github Repositories

Zbxsec-7 About This repository contains a proof-of-concept of a security issue in Zabbix Any user with the "Zabbix Admin" role is able to run custom shell script on the application server in the context of the application user The impact of this will vary, depending on OS, Zabbix version and how/which users are granted the "Zabbix Admin" role, but the user