CVE-2023-32728

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
18/12/2023
Last modified:
22/12/2023

Description

The Zabbix Agent 2 item key smart.disk.get does not sanitize its parameters before passing them to a shell command resulting possible vulnerability for remote code execution.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:zabbix:zabbix-agent2:*:*:*:*:*:*:*:* 5.0.0 (including) 5.0.38 (including)
cpe:2.3:a:zabbix:zabbix-agent2:*:*:*:*:*:*:*:* 6.0.0 (including) 6.0.23 (including)
cpe:2.3:a:zabbix:zabbix-agent2:*:*:*:*:*:*:*:* 6.4.0 (including) 6.4.8 (including)
cpe:2.3:a:zabbix:zabbix-agent2:7.0.0:alpha1:*:*:*:*:*:*
cpe:2.3:a:zabbix:zabbix-agent2:7.0.0:alpha2:*:*:*:*:*:*
cpe:2.3:a:zabbix:zabbix-agent2:7.0.0:alpha3:*:*:*:*:*:*
cpe:2.3:a:zabbix:zabbix-agent2:7.0.0:alpha6:*:*:*:*:*:*
cpe:2.3:a:zabbix:zabbix-agent2:7.0.0:alpha7:*:*:*:*:*:*


References to Advisories, Solutions, and Tools