QID 379538

Date Published: 2024-04-02

QID 379538: Zabbix Agent 2 Code Injection Vulnerability (ZBX-23388)

Zabbix agent 2 is a new generation of Zabbix agent and may be used in place of Zabbix agent. Zabbix agent 2 has been developed to: reduce the number of TCP connections, provide improved concurrency of checks, be easily extendible with plugins.
Agent 2 package are built with Go version affected by CVE-2023-24538
Affected Versions:
Zabbix Agent 2:5.0.0 - 5.0.34
Zabbix Agent 2:6.0.0 - 6.0.17
Zabbix Agent 2:6.4.0 - 6.4.2

QID Detection Logic (Authenticated):
The detection posts vulnerable if the installed package version is installed or not via registry keys.

An attacker can inject code into an application on any device.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution

    The customer has advised to refer Zabbix Agent 2 However, it is recommended to update to a supported version of a product.

    Vendor References

    CVEs related to QID 379538

    Software Advisories
    Advisory ID Software Component Link
    ZBX-23388 URL Logo support.zabbix.com/browse/ZBX-23388