CVE-2024-45700

Zabbix server is vulnerable to a DoS vulnerability due to uncontrolled resource exhaustion. An attacker can send specially crafted requests to the server, which will cause the server to allocate an excessive amount of memory and perform CPU-intensive decompression operations, ultimately leading to a service crash.
References
Link Resource
https://support.zabbix.com/browse/ZBX-26253 Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:*
cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:*
cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:*

History

08 Oct 2025, 14:51

Type Values Removed Values Added
References () https://support.zabbix.com/browse/ZBX-26253 - () https://support.zabbix.com/browse/ZBX-26253 - Vendor Advisory
First Time Zabbix zabbix
Zabbix
CPE cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 6.5
Summary
  • (es) El servidor Zabbix es vulnerable a una vulnerabilidad de denegación de servicio (DoS) debido al agotamiento incontrolado de recursos. Un atacante puede enviar solicitudes especialmente manipuladas al servidor, lo que provocará que este asigne una cantidad excesiva de memoria y realice operaciones de descompresión que consumen mucha CPU, lo que finalmente provocará un bloqueo del servicio.

02 Apr 2025, 07:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-02 07:15

Updated : 2025-10-08 14:51


NVD link : CVE-2024-45700

Mitre link : CVE-2024-45700

CVE.ORG link : CVE-2024-45700


JSON object : View

Products Affected

zabbix

  • zabbix
CWE
CWE-770

Allocation of Resources Without Limits or Throttling