Vulnerabilities > CVE-2022-22704 - Missing Initialization of Resource vulnerability in Zabbix Zabbix-Agent2

047910
CVSS 9.8 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
low complexity
zabbix
CWE-909
critical

Summary

The zabbix-agent2 package before 5.4.9-r1 for Alpine Linux sometimes allows privilege escalation to root because the design incorrectly expected that systemd would (in effect) determine part of the configuration.

Common Weakness Enumeration (CWE)