nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-27233 CVE-2025-27233
MEDIUM
Zabbix Agent 2 smartctl plugin argument injection in Zabbix 6.0 and later.
Record summary
CVE-2025-27233 has a selected CVSS score of 5.7 (medium).
Description
Zabbix Agent 2 smartctl plugin does not properly sanitize smart.disk.get parameters, allowing an attacker to inject unexpected arguments into the smartctl command. This can be used to leak the NTLMv2 hash from a Windows system.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableNo
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 12, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
ZabbixBrowse Zabbix / ZabbixDefault status: unknown | CVE List | 6.0.0 to ≤ 6.0.39 | affected |
| 7.0.0 to ≤ 7.0.10 | affected | ||
| 7.2.0 to ≤ 7.2.4 | affected |
References
2support.zabbix.com
https://support.zabbix.com/browse/ZBX-26987