First published: Mon Dec 18 2023(Updated: )
An attacker who has the privilege to configure Zabbix items can use function icmpping() with additional malicious command inside it to execute arbitrary code on the current Zabbix server.
Credit: security@zabbix.com
Affected Software | Affected Version | How to fix |
---|---|---|
Zabbix Zabbix Server | >=4.0.0<=4.0.49 | |
Zabbix Zabbix Server | >=5.0.0<=5.0.38 | |
Zabbix Zabbix Server | >=6.0.0<=6.0.22 | |
Zabbix Zabbix Server | >=6.4.0<=6.4.7 | |
Zabbix Zabbix Server | =7.0.0-alpha1 | |
Zabbix Zabbix Server | =7.0.0-alpha2 | |
Zabbix Zabbix Server | =7.0.0-alpha3 | |
Zabbix Zabbix Server | =7.0.0-alpha6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.