vendor:
ZoneMinder
by:
Ravindu Wickramasinghe
8.1
CVSS
CRITICAL
Remote Code Execution (RCE)
78
CWE
Product Name: ZoneMinder
Affected Version From: prior to 1.36.33
Affected Version To: 1.37.33
Patch Exists: YES
Related CWE: CVE-2023-26035
CPE: zoneminder
Platforms Tested: Arch Linux, Kali Linux
2023
Unauthenticated RCE in ZoneMinder Snapshots
The exploit allows an unauthenticated attacker to execute arbitrary commands on the vulnerable ZoneMinder instances prior to versions 1.36.33 and 1.37.33. By manipulating a crafted request, the attacker can inject and execute commands on the system. This vulnerability is identified as CVE-2023-26035.
Mitigation:
To mitigate this vulnerability, users are advised to update their ZoneMinder instances to versions 1.36.33 or 1.37.33 or later. Additionally, restrict access to the application to trusted networks only.