An attacker who has the privilege to configure Zabbix items can use function icmpping() with additional malicious command inside it to execute arbitrary code on the current Zabbix server.
2023-12-18T10:15:06.937
2024-11-21T08:03:55.500
Modified
CVSSv3.1: 6.8 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | zabbix | zabbix_server | ≤ 4.0.49 | Yes |
Application | zabbix | zabbix_server | ≤ 5.0.38 | Yes |
Application | zabbix | zabbix_server | ≤ 6.0.22 | Yes |
Application | zabbix | zabbix_server | ≤ 6.4.7 | Yes |
Application | zabbix | zabbix_server | 7.0.0 | Yes |
Application | zabbix | zabbix_server | 7.0.0 | Yes |
Application | zabbix | zabbix_server | 7.0.0 | Yes |
Application | zabbix | zabbix_server | 7.0.0 | Yes |