Vulnerability CVE-2023-32727: Information

Description

An attacker who has the privilege to configure Zabbix items can use function icmpping() with additional malicious command inside it to execute arbitrary code on the current Zabbix server.

Severity: HIGH (7.2) Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Published: Dec. 18, 2023
Modified: Dec. 22, 2023
Error type identifier: CWE-20

Fixed packages

References to Advisories, Solutions, and Tools

Hyperlink
Resource
https://support.zabbix.com/browse/ZBX-23857
  • Vendor Advisory
    1. Configuration 1

      cpe:2.3:a:zabbix:zabbix_server:*:*:*:*:*:*:*:*
      Start including
      4.0.0
      End including
      4.0.49

      cpe:2.3:a:zabbix:zabbix_server:*:*:*:*:*:*:*:*
      Start including
      5.0.0
      End including
      5.0.38

      cpe:2.3:a:zabbix:zabbix_server:*:*:*:*:*:*:*:*
      Start including
      6.0.0
      End including
      6.0.22

      cpe:2.3:a:zabbix:zabbix_server:*:*:*:*:*:*:*:*
      Start including
      6.4.0
      End including
      6.4.7

      cpe:2.3:a:zabbix:zabbix_server:7.0.0:alpha1:*:*:*:*:*:*

      cpe:2.3:a:zabbix:zabbix_server:7.0.0:alpha2:*:*:*:*:*:*

      cpe:2.3:a:zabbix:zabbix_server:7.0.0:alpha3:*:*:*:*:*:*

      cpe:2.3:a:zabbix:zabbix_server:7.0.0:alpha6:*:*:*:*:*:*