Lucene search

K
cve[email protected]CVE-2023-32724
HistoryOct 12, 2023 - 7:15 a.m.

CVE-2023-32724

2023-10-1207:15:10
CWE-732
web.nvd.nist.gov
55
cve-2023-32724
memory pointer
ducktape object
vulnerabilities
direct memory access
manipulation
nvd

9.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H

8.8 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

19.4%

Memory pointer is in a property of the Ducktape object. This leads to multiple vulnerabilities related to direct memory access and manipulation.

Affected configurations

NVD
Node
zabbixzabbixRange5.0.05.0.36
OR
zabbixzabbixRange6.0.06.0.20
OR
zabbixzabbixRange6.4.06.4.5
OR
zabbixzabbixMatch7.0.0alpha1
OR
zabbixzabbixMatch7.0.0alpha2
OR
zabbixzabbixMatch7.0.0alpha3

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "modules": [
      "Proxy",
      "Server"
    ],
    "product": "Zabbix",
    "repo": "https://git.zabbix.com/",
    "vendor": "Zabbix",
    "versions": [
      {
        "changes": [
          {
            "at": "5.0.37rc1",
            "status": "unaffected"
          }
        ],
        "lessThanOrEqual": "5.0.36",
        "status": "affected",
        "version": "5.0.0",
        "versionType": "git"
      },
      {
        "changes": [
          {
            "at": "6.0.21rc1",
            "status": "unaffected"
          }
        ],
        "lessThanOrEqual": "6.0.20",
        "status": "affected",
        "version": "6.0.0",
        "versionType": "git"
      },
      {
        "changes": [
          {
            "at": "6.4.6rc1",
            "status": "unaffected"
          }
        ],
        "lessThanOrEqual": "6.4.5",
        "status": "affected",
        "version": "6.4.0",
        "versionType": "git"
      },
      {
        "changes": [
          {
            "at": "7.0.0alpha4",
            "status": "unaffected"
          }
        ],
        "lessThanOrEqual": "7.0.0alpha3",
        "status": "affected",
        "version": "7.0.0alpha1",
        "versionType": "git"
      }
    ]
  }
]

9.1 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:H

8.8 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

19.4%