An attacker who has the privilege to configure Zabbix items can use function icmpping() with additional malicious command inside it to execute arbitrary code on the current Zabbix server.
References
Link Resource
https://support.zabbix.com/browse/ZBX-23857 Vendor Advisory
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: Zabbix

Published: 2023-12-18T09:18:48.446Z

Updated: 2023-12-18T09:18:48.446Z

Reserved: 2023-05-11T21:25:43.368Z


Link: CVE-2023-32727

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2023-12-18T10:15:06.937

Modified: 2023-12-22T17:48:43.190


Link: CVE-2023-32727

JSON object: View

cve-icon Redhat Information

No data.

CWE