CVE-2023-32727
18.12.2023, 10:15
An attacker who has the privilege to configure Zabbix items can use function icmpping() with additional malicious command inside it to execute arbitrary code on the current Zabbix server.Enginsight
Vendor | Product | Version |
---|---|---|
zabbix | zabbix_server | 4.0.0 ≤ 𝑥 ≤ 4.0.49 |
zabbix | zabbix_server | 5.0.0 ≤ 𝑥 ≤ 5.0.38 |
zabbix | zabbix_server | 6.0.0 ≤ 𝑥 ≤ 6.0.22 |
zabbix | zabbix_server | 6.4.0 ≤ 𝑥 ≤ 6.4.7 |
zabbix | zabbix_server | 7.0.0:alpha1 |
zabbix | zabbix_server | 7.0.0:alpha2 |
zabbix | zabbix_server | 7.0.0:alpha3 |
zabbix | zabbix_server | 7.0.0:alpha6 |
𝑥
= Vulnerable software versions

Debian Releases

Ubuntu Releases
Common Weakness Enumeration