CVE-2025-27234 - Zabbix Agent 2 smartctl plugin RCE vulnerability in Zabbix 5.0.
CVE ID : CVE-2025-27234
Published : Sept. 12, 2025, 11:15 a.m. | 48 minutes ago
Description : Zabbix Agent 2 smartctl plugin does not properly sanitize smart.disk.get parameters, allowing an attacker to inject unexpected arguments into the smartctl command. In Zabbix 5.0 this allows for remote code execution.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Sept. 12, 2025, 11:15 a.m. | 48 minutes ago
Description : Zabbix Agent 2 smartctl plugin does not properly sanitize smart.disk.get parameters, allowing an attacker to inject unexpected arguments into the smartctl command. In Zabbix 5.0 this allows for remote code execution.
Severity: 7.3 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...