QID 150764
Date Published: 2023-12-25
QID 150764: Zabbix Code Execution Vulnerability (CVE-2023-32727)
Zabbix is an open-source software tool to monitor IT infrastructure such as networks, servers, virtual machines, and cloud services.
An attacker who has the privilege to configure Zabbix items can use function icmpping() with additional malicious command inside it to execute arbitrary code on the current Zabbix server.
Affected version:
Zabbix version from 4.0.0 to 4.0.49
Zabbix version from 5.0.0 to 5.0.38
Zabbix version from 6.0.0 to 6.0.22
Zabbix version from 6.4.0 to 6.4.7
QID Detection Logic (Unauthenticated):
This QID sends a HTTP POST request to "api_jsonrpc.php" endpoint and checks the response body to confirm if the host is running vulnerable version of Zabbix Server.
Successful exploitation of this vulnerability could allow a remote attacker to run arbitrary shell commands on the target system.
- ZBX-23857 -
support.zabbix.com/browse/ZBX-23857
CVEs related to QID 150764
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ZBX-23857 |
|