TROYANOSYVIRUS
Voltar para CVEs

CVE-2025-27233

N/A

Descricao

Zabbix Agent 2 smartctl plugin does not properly sanitize smart.disk.get parameters, allowing an attacker to inject unexpected arguments into the smartctl command. This can be used to leak the NTLMv2 hash from a Windows system.

Detalhes CVE

Pontuacao CVSS v3.1N/A
Publicado9/12/2025
Ultima modificacao9/15/2025
Fontenvd
Avistamentos honeypot0

Fraquezas (CWE)

CWE-77

Referencias

Correlacoes IOC

Sem correlacoes registradas

This product uses data from the NVD API but is not endorsed or certified by the NVD.