CVE-2025-27234: Zabbix Agent 2 smartctl plugin RCE vulnerability in Zabbix 5.0.
Zabbix Agent 2 smartctl plugin does not properly sanitize smart.disk.get parameters, allowing an attacker to inject unexpected arguments into the smartctl command. In Zabbix 5.0 this allows for remote code execution.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-27234?
CVE-2025-27234 is rated as critical due to its potential for remote code execution through improper parameter sanitization.
How do I fix CVE-2025-27234?
To fix CVE-2025-27234, update to the latest version of Zabbix that includes the patch addressing this vulnerability.
What products are affected by CVE-2025-27234?
CVE-2025-27234 affects Zabbix Agent 2, specifically the smartctl plugin.
Can CVE-2025-27234 be exploited remotely?
Yes, CVE-2025-27234 can be exploited remotely due to its vulnerability in the Zabbix Agent 2.
What implications does CVE-2025-27234 have for Zabbix users?
Zabbix users may face significant security risks, including potential remote code execution attacks if CVE-2025-27234 is not mitigated.