QID 731046
Date Published: 2023-12-27
QID 731046: Zabbix Server Arbitrary Code Execution Vulnerability (ZBX-23857)
Zabbix is an open-source software tool to monitor IT infrastructure such as networks, servers, virtual machines, and cloud services.
An attacker who has the privilege to configure Zabbix items can use function icmpping() with additional malicious command inside it to execute arbitrary code on the current Zabbix server.
Affected version:
Zabbix Server version from 4.0.0 to 4.0.49
Zabbix Server version from 5.0.0 to 5.0.38
Zabbix Server version from 6.0.0 to 6.0.22
Zabbix Server version from 6.4.0 to 6.4.7
Zabbix Server version from 7.0.0alpha0 to 7.0.0alpha6
QID Detection Logic (Unauthenticated):
This QID sends a HTTP POST request to "api_jsonrpc.php" endpoint and checks the response body to confirm if the host is running vulnerable version of Zabbix Server.
This QID checks for installed zabbix server on default (i.e root) or /zabbix directory.
Successful exploitation of this vulnerability could allow a remote attacker to run arbitrary shell commands on the target system.
- ZBX-23857 -
support.zabbix.com/browse/ZBX-23857
CVEs related to QID 731046
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ZBX-23857 |
|