CVE-2025-27233 - Zabbix Agent 2 smartctl plugin argument injection in Zabbix 6.0 and later.
CVE ID : CVE-2025-27233
Published : Sept. 12, 2025, 11:15 a.m. | 48 minutes ago
Description : Zabbix Agent 2 smartctl plugin does not properly sanitize smart.disk.get parameters, allowing an attacker to inject unexpected arguments into the smartctl command. This can be used to leak the NTLMv2 hash from a Windows system.
Severity: 5.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : Sept. 12, 2025, 11:15 a.m. | 48 minutes ago
Description : Zabbix Agent 2 smartctl plugin does not properly sanitize smart.disk.get parameters, allowing an attacker to inject unexpected arguments into the smartctl command. This can be used to leak the NTLMv2 hash from a Windows system.
Severity: 5.7 | MEDIUM
Visit the link for more details, such as CVSS details, affected products, timeline, and more...