An attacker who has the privilege to configure Zabbix items can use function icmpping() with additional malicious command inside it to execute arbitrary code on the current Zabbix server.
2023-12-18T10:15:06.937
2025-11-03T22:16:22.293
Modified
CVSSv3.1: 6.8 (MEDIUM)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | zabbix | zabbix_server | ≤ 4.0.49 | Yes |
| Application | zabbix | zabbix_server | ≤ 5.0.38 | Yes |
| Application | zabbix | zabbix_server | ≤ 6.0.22 | Yes |
| Application | zabbix | zabbix_server | ≤ 6.4.7 | Yes |
| Application | zabbix | zabbix_server | 7.0.0 | Yes |
| Application | zabbix | zabbix_server | 7.0.0 | Yes |
| Application | zabbix | zabbix_server | 7.0.0 | Yes |
| Application | zabbix | zabbix_server | 7.0.0 | Yes |