← Back

CVE-2023-32728

nvd nist
Published: Dec 18, 2023Modified: Jun 17, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

The Zabbix Agent 2 item key smart.disk.get does not sanitize its parameters before passing them to a shell command resulting possible vulnerability for remote code execution.

Affected (8)

1 product
Zabbix Agent2
Configuration A
8 vulnerable
Vulnerable SoftwareAffected Versions
Zabbix
From 5.0.0 to 5.0.38
From 6.0.0 to 6.0.23
From 6.4.0 to 6.4.8
Version 7.0.0 alpha1
Version 7.0.0 alpha2
Version 7.0.0 alpha3
Version 7.0.0 alpha6
Version 7.0.0 alpha7

References (2)

Source: security@zabbix.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.