An attacker who has the privilege to configure Zabbix items can use function icmpping() with additional malicious command inside it to execute arbitrary code on the current Zabbix server.
| Software | From | Fixed in |
|---|---|---|
| zabbix / zabbix_server | 4.0.0 | 4.0.49.x |
| zabbix / zabbix_server | 5.0.0 | 5.0.38.x |
| zabbix / zabbix_server | 6.0.0 | 6.0.22.x |
| zabbix / zabbix_server | 6.4.0 | 6.4.7.x |
| zabbix / zabbix_server | 7.0.0-alpha1 | 7.0.0-alpha1.x |
| zabbix / zabbix_server | 7.0.0-alpha2 | 7.0.0-alpha2.x |
| zabbix / zabbix_server | 7.0.0-alpha3 | 7.0.0-alpha3.x |
| zabbix / zabbix_server | 7.0.0-alpha6 | 7.0.0-alpha6.x |