Description
Zabbix Agent 2 smartctl plugin does not properly sanitize smart.disk.get parameters, allowing an attacker to inject unexpected arguments into the smartctl command. This can be used to leak the NTLMv2 hash from a Windows system.
Problem types
CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')
Product status
6.0.0 (git)
7.0.0 (git)
7.2.0 (git)
Credits
Zabbix wants to thank kelsier for submitting this report on the HackerOne bug bounty platform.
References
support.zabbix.com/browse/ZBX-26987