CVSS v3
9.8
CRITICAL
EPSS Score
49.6 %
exploit probability
CISA KEV
No
known exploited
Exploitation
—
SSVC status
Description
ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 are vulnerable to Unauthenticated Remote Code Execution via Missing Authorization. There are no permissions check on the snapshot action, which expects an id to fetch an existing monitor but can be passed an object to create a new one instead. TriggerOn ends up calling shell_exec using the supplied Id. This issue is fixed in This issue is fixed in versions 1.36.33 and 1.37.33.
Technical details
- Published
- 2023-02-25
Frequently asked questions
What is CVE-2023-26035?
ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 are vulnerable to Unauthenticated Remote Code Execution via Missing Authorization. There are no permissions check on the snapshot action, which expects an id to fetch an existing monitor but can be passed an object to create a new one instead. TriggerOn ends up calling shell_exec using the supplied Id. This issue is fixed in This issue is fixed in versions 1.36.33 and 1.37.33.
Is CVE-2023-26035 actively exploited?
Active exploitation of CVE-2023-26035 has not been confirmed. The EPSS score is 49.6%, indicating the estimated probability of exploitation in the next 30 days.
What is the CVSS score for CVE-2023-26035?
CVE-2023-26035 has a CVSS v3 base score of 9.8 (CRITICAL severity).
Is CVE-2023-26035 affecting your environment?
Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.
No credit card required · 500 free checks/month · Free API key
Other 2023 vulnerabilities worth triaging
Ranked by exploit probability (EPSS).