CVE-2023-32728: Code injection in zabbix_agent2 smart.disk.get caused by smartctl plugin
Published Dec 18, 2023
·Updated
The Zabbix Agent 2 item key smart.disk.get does not sanitize its parameters before passing them to a shell command resulting possible vulnerability for remote code execution.
Affected Software
8 affected components
Zabbix zabbix-agent2>=5.0.0<=5.0.38
Zabbix zabbix-agent2>=6.0.0<=6.0.23
Zabbix zabbix-agent2>=6.4.0<=6.4.8
Zabbix zabbix-agent2=7.0.0-alpha1
Zabbix zabbix-agent2=7.0.0-alpha2
Zabbix zabbix-agent2=7.0.0-alpha3
Zabbix zabbix-agent2=7.0.0-alpha6
Zabbix zabbix-agent2=7.0.0-alpha7
Event History
Dec 18, 2023
CVE Published
09:19 AM
Data Sourced
09:19 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2023-32728?
CVE-2023-32728 is considered a critical vulnerability due to its potential for remote code execution.
2
How do I fix CVE-2023-32728?
To fix CVE-2023-32728, update your Zabbix Agent 2 to a version that addresses this issue.
3
Which versions are affected by CVE-2023-32728?
CVE-2023-32728 affects Zabbix Agent 2 versions from 5.0.0 to 5.0.38, 6.0.0 to 6.0.23, 6.4.0 to 6.4.8, and several alpha versions of 7.0.0.
4
What is the exploitability of CVE-2023-32728?
CVE-2023-32728 can potentially be exploited by an attacker to execute arbitrary commands on a vulnerable system.
5
What types of systems are vulnerable to CVE-2023-32728?
Systems running affected versions of Zabbix Agent 2 without necessary mitigations are vulnerable to CVE-2023-32728.