An attacker who has the privilege to configure Zabbix items can use function icmpping() with additional malicious command inside it to execute arbitrary code on the current Zabbix server.
References
Link | Resource |
---|---|
https://support.zabbix.com/browse/ZBX-23857 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2023-12-18 10:15
Updated : 2023-12-22 17:48
NVD link : CVE-2023-32727
Mitre link : CVE-2023-32727
CVE.ORG link : CVE-2023-32727
JSON object : View
Products Affected
zabbix
- zabbix_server
CWE
CWE-20
Improper Input Validation