« Volver al listado

CVE-2023-32728

Estado: ModificadaCrítica (9.8)—

The Zabbix Agent 2 item key smart.disk.get does not sanitize its parameters before passing them to a shell command resulting possible vulnerability for remote code execution.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-32728",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-32728",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-11-27T20:43:15.626286Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@zabbix.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.6,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L",
          "integrityImpact": "LOW",
          "userInteraction": "REQUIRED",
          "attackComplexity": "HIGH",
          "availabilityImpact": "LOW",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 3.4,
        "exploitabilityScore": 1.2
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security@zabbix.com",
      "affectedData": [
        {
          "repo": "https://git.zabbix.com/",
          "vendor": "Zabbix",
          "modules": [
            "Agent 2"
          ],
          "product": "Zabbix",
          "versions": [
            {
              "status": "affected",
              "changes": [
                {
                  "at": "5.0.39rc1",
                  "status": "unaffected"
                }
              ],
              "version": "5,0,0",
              "versionType": "git",
              "lessThanOrEqual": "5.0.38"
            },
            {
              "status": "affected",
              "changes": [
                {
                  "at": "6.0.24rc1",
                  "status": "unaffected"
                }
              ],
              "version": "6.0.0",
              "versionType": "git",
              "lessThanOrEqual": "6.0.23"
            },
            {
              "status": "affected",
              "changes": [
                {
                  "at": "6.4.9rc1",
                  "status": "unaffected"
                }
              ],
              "version": "6.4.0",
              "versionType": "git",
              "lessThanOrEqual": "6.4.8 "
            },
            {
              "status": "affected",
              "changes": [
                {
                  "at": "7.0.0alpha8",
                  "status": "unaffected"
                }
              ],
              "version": "7.0.0alpha1",
              "versionType": "git",
              "lessThanOrEqual": "7.0.0alpha7 "
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-12-18T10:15:07.127",
  "references": [
    {
      "url": "https://support.zabbix.com/browse/ZBX-23858",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@zabbix.com"
    },
    {
      "url": "https://support.zabbix.com/browse/ZBX-23858",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@zabbix.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-20"
        }
      ]
    },
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-94"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The Zabbix Agent 2 item key smart.disk.get does not sanitize its parameters before passing them to a shell command resulting possible vulnerability for remote code execution."
    },
    {
      "lang": "es",
      "value": "La clave del elemento Zabbix Agent 2 smart.disk.get no sanitiza sus parámetros antes de pasarlos a un comando de shell, lo que resulta en una posible vulnerabilidad de ejecución remota de código."
    }
  ],
  "lastModified": "2026-06-17T05:59:28.170",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:zabbix:zabbix-agent2:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0540AFD4-08E7-4102-BA3C-C5C81EF26C1E",
              "versionEndIncluding": "5.0.38",
              "versionStartIncluding": "5.0.0"
            },
            {
              "criteria": "cpe:2.3:a:zabbix:zabbix-agent2:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "117E1E38-FD93-4F56-A6B8-676BC480C87B",
              "versionEndIncluding": "6.0.23",
              "versionStartIncluding": "6.0.0"
            },
            {
              "criteria": "cpe:2.3:a:zabbix:zabbix-agent2:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "067A0B9D-D87C-4FB5-B704-49E19750CEB9",
              "versionEndIncluding": "6.4.8",
              "versionStartIncluding": "6.4.0"
            },
            {
              "criteria": "cpe:2.3:a:zabbix:zabbix-agent2:7.0.0:alpha1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "05554FEE-2F59-42F7-89AC-93B46F3A0E7C"
            },
            {
              "criteria": "cpe:2.3:a:zabbix:zabbix-agent2:7.0.0:alpha2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6D87F6BC-E7F0-454D-8E02-608448A0CAA8"
            },
            {
              "criteria": "cpe:2.3:a:zabbix:zabbix-agent2:7.0.0:alpha3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4689D927-9759-45A7-B045-BA6F2B079A15"
            },
            {
              "criteria": "cpe:2.3:a:zabbix:zabbix-agent2:7.0.0:alpha6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "178E0AC4-233F-46E0-87BD-830A30A6283A"
            },
            {
              "criteria": "cpe:2.3:a:zabbix:zabbix-agent2:7.0.0:alpha7:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "8D2574B9-F936-4D98-A53F-1C7EC8FBB49E"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@zabbix.com"
}