Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2024-42327 — AI Deep Analysis Summary

CVSS 9.9 · Critical

Q1What is this vulnerability? (Essence + Consequences)

🚨 **Essence**: Zabbix suffers from a critical **SQL Injection (SQLi)** flaw.…

Q2Root Cause? (CWE/Flaw)

🛡️ **Root Cause**: **CWE-89** (SQL Injection). The flaw resides in the `CUser` class, specifically within the `addRelatedObjects` function.…

Q3Who is affected? (Versions/Components)

📦 **Affected Versions**: • **6.0.0** to **6.0.31** • **6.4.0** to **6.4.16** • **7.0.0** 🔧 **Component**: Zabbix Frontend API (specifically User API endpoints).

Q4What can hackers do? (Privileges/Data)

🕵️ **Attacker Capabilities**: • **Privileges**: Requires only **API access** (even default 'User' role). No admin rights needed! 🤯 • **Data**: Can read, modify, or delete database content.…

Q5Is exploitation threshold high? (Auth/Config)

🔓 **Exploitation Threshold**: **LOW**. • **Auth**: Requires **Authentication** (valid user account). • **Config**: Default 'User' role is sufficient. • **UI**: No user interaction needed (Non-interactive).…

Q6Is there a public Exp? (PoC/Wild Exploitation)

💣 **Public Exploits**: **YES**. Multiple PoCs are available on GitHub (e.g., `aramosf`, `compr00t`, `depers-rus`). Wild exploitation is likely as the mechanism is well-documented. ⚠️

Q7How to self-check? (Features/Scanning)

🔍 **Self-Check**: 1. Check your Zabbix version against the affected list. 2. Scan for API endpoints using `user.get`. 3. Use automated scanners targeting **CWE-89** in Zabbix APIs. 4.…

Q8Is it fixed officially? (Patch/Mitigation)

✅ **Official Fix**: **YES**. • **6.0.32rc1** • **6.4.17rc1** • **7.0.1rc1** 🔧 **Action**: Upgrade immediately to these fixed versions or later.

Q9What if no patch? (Workaround)

🚧 **No Patch Workaround**: • **Restrict API Access**: Disable API access for non-essential users. • **Network Segmentation**: Block external access to Zabbix API ports.…

Q10Is it urgent? (Priority Suggestion)

🔥 **Urgency**: **CRITICAL**. • **CVSS**: High (9.8/10 approx). • **Impact**: Full database compromise. • **Ease**: Low barrier to entry (standard user role). 🚀 **Priority**: Patch immediately! Do not wait.