APP: Zabbix Audit Log SQL Injection

This signature detects attempts to exploit a known vulnerability against Zabbix. A successful attack can lead to command injection and arbitrary code execution.

Extended Description

Zabbix server can perform command execution for configured scripts. After command is executed, audit entry is added to "Audit Log". Due to "clientip" field is not sanitized, it is possible to injection SQL into "clientip" and exploit time based blind SQL injection.

Short Name
APP:MISC:ZABBIX-AUDIT-LOG
Severity
Critical
Recommended
False
Recommended Action
Drop
Category
APP
Keywords
Audit CVE-2024-22120 Injection Log SQL Zabbix
Release Date
06/14/2024
Supported Platforms

srx-branch-19.3

vsrx3bsd-19.2

srx-19.4

vsrx3bsd-19.4

srx-branch-19.4

vsrx-19.4

vsrx-19.2

srx-19.3

Sigpack Version
3714
False Positive
Unknown

Found a potential security threat?