
Cloud Vulnerability DB
A community-led vulnerabilities database
Zabbix server has been identified with a Denial of Service (DoS) vulnerability tracked as CVE-2024-45700, discovered and disclosed on April 2, 2025. The vulnerability affects multiple versions of Zabbix server software, including versions in Debian distributions bullseye and bookworm (Debian Tracker).
The vulnerability is classified as a resource exhaustion issue (CWE-770) that occurs due to uncontrolled resource allocation. The CVSS v4.0 score assigned by Zabbix is 6.0 (Medium) with the vector string CVSS:4.0/AV:A/AC:L/AT:P/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N (NVD).
When exploited, the vulnerability can cause the Zabbix server to crash through excessive memory allocation and CPU-intensive decompression operations. This can result in service disruption and unavailability of the Zabbix monitoring system (NVD).
An attacker can trigger this vulnerability by sending specially crafted requests to the server. The attack requires no user interaction or special privileges, making it relatively straightforward to exploit (NVD).
A fix has been implemented in Zabbix version 7.0.10+dfsg-2 for Debian trixie and sid distributions. Users of affected versions should upgrade to the fixed version when available (Debian Tracker).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."