S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
critical·Product Based Web Vulnerabilities·Updated Oct 8, 2024

CVE-2023-26035 Scanner

CVE-2023-26035 Scanner - Remote Code Execution (RCE) vulnerability in ZoneMinder

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, ipv4, subdomain
CostFree
3.4k
Times Used
continuous scan runs
4.1k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2023-26035
9.8
CVSShigh
Exploitable remotely over the internet · no authentication required.

ZoneMinder is a free, open source Closed-circuit television software application for Linux which supports IP, USB and Analog cameras. Versions prior to 1.36.33 and 1.37.33 are vulnerable to Unauthenticated Remote Code Execution via Missing Authorization. There are no permissions check on the snapshot action, which expects an id to fetch an existing monitor but can be passed an object to create a new one instead. TriggerOn ends up calling shell_exec using the supplied Id. This issue is fixed in This issue is fixed in versions 1.36.33 and 1.37.33.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
zoneminderby ZoneMinder
< 1.36.33
Updated Aug 22, 2026View on NVD →
Detail

ZoneMinder is utilized by institutions and individuals needing advanced surveillance capabilities. It supports a range of camera types, including IP, USB, and Analog, and operates primarily on Linux systems. Notably, it's an open-source alternative, which makes it a cost-effective solution for various monitoring needs. Administrators and IT managers applaud its comprehensive functionality tailored for security purposes. Many deploy ZoneMinder in environments where monitoring multiple camera feeds is crucial. Its flexibility and open-source nature cater to diverse operational requirements in surveillance.

The vulnerability identified pertains to Command Injection, a severe flaw in ZoneMinder. It arises from inadequate authorization checks in snapshot actions which are accessible without authentication. This flaw permits unauthorized users to execute arbitrary commands via crafting specific requests. With the vulnerability hinged on shell execution functions, attackers can manipulate inputs to gain unauthorized access and control. The potential for remote code execution highlights the critical nature of this vulnerability. Ensuring proper authorization on all endpoints would mitigate this risk.

Technical details reveal that the vulnerable endpoint is the snapshot action URL, where improper checks lead to exposure. Attackers exploit this by manipulating the ‘id’ parameter, normally required to fetch an existing monitor snapshot. Instead, they can inject commands that the server erroneously processes and executes. The absence of permissions checks compounds the risk, as any unauthenticated user is provided with this access. Employing shell_exec calls increases vulnerability intensity by allowing any command injected via user input. Addressing such issues involves implementing stricter access controls and sanitizing inputs before processing.

If exploited, this vulnerability allows attackers to execute arbitrary commands at the server level, leading to various malicious outcomes. Unauthorized access to system functions can compromise data integrity and confidentiality. Attackers might deploy scripts or malware, disrupt services, or exfiltrate sensitive information, thereby breaching the secure operational environment. The possible repercussions emphasize the importance of immediate remediation to prevent system exploitation. Failure to mitigate can expose systems to prolonged unauthorized access, leading to data breaches or loss of operational functionality.

REFERENCES

Solution Advice
  • Update ZoneMinder to versions 1.36.33 or 1.37.33 as these versions have fixed the vulnerability.
  • Implement strict access controls and authorization checks on sensitive endpoints.
  • Regularly review and sanitize input data to avoid execution of unauthorized commands.
  • Monitor system logs for unusual activities that may indicate attempted exploitation.
  • Consider deploying a web application firewall (WAF) to help detect and block injection attempts.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.