PT-2023-8056 · Zabbix+4 · Zabbix+4

Catenacyber

+1

·

Published

2023-12-18

·

Updated

2024-10-03

·

CVE-2023-32727

CVSS v2.0

8.3

High

VectorAV:N/AC:L/Au:M/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Zabbix (affected versions not specified)
Description The issue is related to errors in processing input data in the icmpping function of the Zabbix monitoring system. This can allow a remote attacker to execute arbitrary code. An attacker with privileges to configure Zabbix items can use the icmpping() function with an additional malicious command to achieve this. The estimated number of potentially affected devices and details about real-world incidents are not provided.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2024-1355
ALT-PU-2024-1356
ALT-PU-2024-1565
ALT-PU-2024-3075
ALT-PU-2024-3077
ALT-PU-2024-3365
BDU:2024-00033
CVE-2023-32727
DLA-3909-1
OPENSUSE-SU-2023:0418-1
OPENSUSE-SU-2023:0419-1
OPENSUSE-SU-2024:13535-1

Affected Products

Alt Linux
Astra Linux
Debian
Red Os
Zabbix