The Zabbix Agent 2 item key smart.disk.get does not sanitize its parameters before passing them to a shell command resulting possible vulnerability for remote code execution.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:LZabbix Agent2
APPZabbix7.0.05.0.0 – 5.0.386.0.0 – 6.0.236.4.0 – 6.4.8
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
Related vulnerabilities
CVE-2023-29453CRITICAL9.8PL ✓same product
Wstrzyknięcie kodu JavaScript w szablonach Go w Zabbix-Agent2
CVE-2022-22704CRITICAL9.8PL ✓same product
Privilege escalation do root w zabbix-agent2 na Alpine Linux
CVE-2022-46768MEDIUM5.9same product
Arbitrary file read vulnerability exists in Zabbix Web Service Report Generation, which listens on the port 10...
CVE-2022-23131CRITICAL9.1⚠ KEVPL ✓same vendor
Zabbix SAML SSO — privilege escalation do konta administratora
CVE-2024-42327CRITICAL9.9PL ✓same vendor
SQL Injection w Zabbix – podatność w klasie CUser umożliwia eskalację uprawnień