QID 379260
Date Published: 2024-02-09
QID 379260: Zabbix Agent 2 Smartctl Plugin Code Injection Vulnerability (ZBX-23858)
Zabbix agent 2 is a new generation of Zabbix agent and may be used in place of Zabbix agent. Zabbix agent 2 has been developed to: reduce the number of TCP connections, provide improved concurrency of checks, be easily extendible with plugins.
The Zabbix Agent 2 item key smart.disk.get does not sanitize its parameters before passing them to a shell command resulting possible vulnerability for remote code execution.
Affected Versions:
Zabbix Agent 2:5.0.0 - 5.0.38
Zabbix Agent 2:6.0.0 - 6.0.23
Zabbix Agent 2:6.4.0 - 6.4.8
Zabbix Agent 2:7.0.0alpha1 - 7.0.0alpha7
QID Detection Logic (Authenticated):
The detection posts vulnerable if the installed package version is installed or not via registry keys.
An attacker can execute arbitrary code on any device having an Zabbix Agent2 listening and having smartctl installed.
Workaround:
Fatal error: Call to undefined function set_session() in /home/web/vulnoffice.intranet.qualys.com/en/internal/newoffice/main/get_securityfocus_workarounds.php on line 6
- Zabbix Advisory -
support.zabbix.com/browse/ZBX-23858
CVEs related to QID 379260
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ZBX-23858 |
|