The Zabbix Agent 2 item key smart.disk.get does not sanitize its parameters before passing them to a shell command resulting possible vulnerability for remote code execution.
2023-12-18T10:15:07.127
2024-11-21T08:03:55.640
Modified
CVSSv3.1: 4.6 (MEDIUM)
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | zabbix | zabbix-agent2 | ≤ 5.0.38 | Yes |
Application | zabbix | zabbix-agent2 | ≤ 6.0.23 | Yes |
Application | zabbix | zabbix-agent2 | ≤ 6.4.8 | Yes |
Application | zabbix | zabbix-agent2 | 7.0.0 | Yes |
Application | zabbix | zabbix-agent2 | 7.0.0 | Yes |
Application | zabbix | zabbix-agent2 | 7.0.0 | Yes |
Application | zabbix | zabbix-agent2 | 7.0.0 | Yes |
Application | zabbix | zabbix-agent2 | 7.0.0 | Yes |