PT-2023-9376 · Zabbix+3 · Zabbix+3

Pavel Voit

+1

·

Published

2023-08-14

·

Updated

2024-12-10

·

CVE-2023-32724

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H
Name of the Vulnerable Software and Affected Versions Zabbix (affected versions not specified)
Description The issue is related to incorrect permission assignment for a critical resource in the Zabbix monitoring system. Exploitation of this issue may allow a remote attacker to access confidential data, compromise its integrity, and cause a denial of service. Additionally, there is a problem with a memory pointer in a property of the Ducktape object, which can lead to vulnerabilities related to direct memory access and manipulation.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Permission

Weakness Enumeration

Related Identifiers

ALT-PU-2024-1565
BDU:2024-06936
CVE-2023-32724
DLA-3909-1
ROSA-SA-2024-2539

Affected Products

Alt Linux
Astra Linux
Debian
Zabbix