« Volver al listado

CVE-2024-45700

Estado: ModificadaMedia (6)—

Zabbix server is vulnerable to a DoS vulnerability due to uncontrolled resource exhaustion. An attacker can send specially crafted requests to the server, which will cause the server to allocate an excessive amount of memory and perform CPU-intensive decompression operations, ultimately leading to a service crash.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2024-45700",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2024-45700",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-04-02T16:27:38.059075Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.5,
          "attackVector": "ADJACENT_NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "NONE"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.8
      }
    ],
    "cvssMetricV40": [
      {
        "type": "Secondary",
        "source": "security@zabbix.com",
        "cvssData": {
          "Safety": "NOT_DEFINED",
          "version": "4.0",
          "Recovery": "NOT_DEFINED",
          "baseScore": 6,
          "Automatable": "NOT_DEFINED",
          "attackVector": "ADJACENT",
          "baseSeverity": "MEDIUM",
          "valueDensity": "NOT_DEFINED",
          "vectorString": "CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
          "exploitMaturity": "NOT_DEFINED",
          "providerUrgency": "NOT_DEFINED",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "attackRequirements": "PRESENT",
          "privilegesRequired": "NONE",
          "subIntegrityImpact": "NONE",
          "vulnIntegrityImpact": "NONE",
          "integrityRequirement": "NOT_DEFINED",
          "modifiedAttackVector": "NOT_DEFINED",
          "subAvailabilityImpact": "NONE",
          "vulnAvailabilityImpact": "HIGH",
          "availabilityRequirement": "NOT_DEFINED",
          "modifiedUserInteraction": "NOT_DEFINED",
          "modifiedAttackComplexity": "NOT_DEFINED",
          "subConfidentialityImpact": "NONE",
          "vulnConfidentialityImpact": "NONE",
          "confidentialityRequirement": "NOT_DEFINED",
          "modifiedAttackRequirements": "NOT_DEFINED",
          "modifiedPrivilegesRequired": "NOT_DEFINED",
          "modifiedSubIntegrityImpact": "NOT_DEFINED",
          "modifiedVulnIntegrityImpact": "NOT_DEFINED",
          "vulnerabilityResponseEffort": "NOT_DEFINED",
          "modifiedSubAvailabilityImpact": "NOT_DEFINED",
          "modifiedVulnAvailabilityImpact": "NOT_DEFINED",
          "modifiedSubConfidentialityImpact": "NOT_DEFINED",
          "modifiedVulnConfidentialityImpact": "NOT_DEFINED"
        }
      }
    ]
  },
  "affected": [
    {
      "source": "security@zabbix.com",
      "affectedData": [
        {
          "repo": "https://git.zabbix.com/",
          "vendor": "Zabbix",
          "modules": [
            "Zabbix Server",
            "Zabbix Proxy"
          ],
          "product": "Zabbix",
          "versions": [
            {
              "status": "affected",
              "changes": [
                {
                  "at": "6.0.39rc1",
                  "status": "unaffected"
                }
              ],
              "version": "6.0.0",
              "versionType": "git",
              "lessThanOrEqual": "6.0.38"
            },
            {
              "status": "affected",
              "changes": [
                {
                  "at": "7.0.10rc1",
                  "status": "unaffected"
                }
              ],
              "version": "7.0.0",
              "versionType": "git",
              "lessThanOrEqual": "7.0.9"
            },
            {
              "status": "affected",
              "changes": [
                {
                  "at": "7.2.4rc1",
                  "status": "unaffected"
                }
              ],
              "version": "7.2.0",
              "versionType": "git",
              "lessThanOrEqual": "7.2.3"
            },
            {
              "status": "unaffected",
              "version": "7.4.0alpha1",
              "versionType": "git"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2025-04-02T07:15:41.570",
  "references": [
    {
      "url": "https://support.zabbix.com/browse/ZBX-26253",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@zabbix.com"
    },
    {
      "url": "https://lists.debian.org/debian-lts-announce/2025/04/msg00027.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@zabbix.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-770"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Zabbix server is vulnerable to a DoS vulnerability due to uncontrolled resource exhaustion. An attacker can send specially crafted requests to the server, which will cause the server to allocate an excessive amount of memory and perform CPU-intensive decompression operations, ultimately leading to a service crash."
    },
    {
      "lang": "es",
      "value": "El servidor Zabbix es vulnerable a una vulnerabilidad de denegación de servicio (DoS) debido al agotamiento incontrolado de recursos. Un atacante puede enviar solicitudes especialmente manipuladas al servidor, lo que provocará que este asigne una cantidad excesiva de memoria y realice operaciones de descompresión que consumen mucha CPU, lo que finalmente provocará un bloqueo del servicio."
    }
  ],
  "lastModified": "2026-06-17T07:54:41.127",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "26D037B9-13AD-42A2-A27D-3E602D59905C",
              "versionEndExcluding": "6.0.39",
              "versionStartIncluding": "6.0.0"
            },
            {
              "criteria": "cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A05AD4B6-5D1F-4908-BF18-26A374C00076",
              "versionEndExcluding": "7.0.10",
              "versionStartIncluding": "7.0.0"
            },
            {
              "criteria": "cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B97B1777-3AA2-4756-A6FF-2D7A2735B350",
              "versionEndExcluding": "7.2.4",
              "versionStartIncluding": "7.2.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@zabbix.com"
}