An attacker who has the privilege to configure Zabbix items can use function icmpping() with additional malicious command inside it to execute arbitrary code on the current Zabbix server.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://support.zabbix.com/browse/ZBX-23857 |
|
History
Wed, 07 May 2025 21:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: Zabbix
Published: 2023-12-18T09:18:48.446Z
Updated: 2025-05-07T20:37:43.796Z
Reserved: 2023-05-11T21:25:43.368Z
Link: CVE-2023-32727
Updated: 2024-08-02T15:25:36.967Z
Status : Modified
Published: 2023-12-18T10:15:06.937
Modified: 2024-11-21T08:03:55.500
Link: CVE-2023-32727
No data.