{"id":"CVE-2023-32728","details":"The Zabbix Agent 2 item key smart.disk.get does not sanitize its parameters before passing them to a shell command resulting possible vulnerability for remote code execution.","modified":"2026-03-14T12:07:05.809622Z","published":"2023-12-18T10:15:07.127Z","references":[{"type":"ADVISORY","url":"https://support.zabbix.com/browse/ZBX-23858"}],"affected":[{"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-32728.json","unresolved_ranges":[{"events":[{"introduced":"5.0.0"},{"last_affected":"5.0.38"}]},{"events":[{"introduced":"6.0.0"},{"last_affected":"6.0.23"}]},{"events":[{"introduced":"6.4.0"},{"last_affected":"6.4.8"}]},{"events":[{"introduced":"0"},{"last_affected":"7.0.0-alpha1"}]},{"events":[{"introduced":"0"},{"last_affected":"7.0.0-alpha2"}]},{"events":[{"introduced":"0"},{"last_affected":"7.0.0-alpha3"}]},{"events":[{"introduced":"0"},{"last_affected":"7.0.0-alpha6"}]},{"events":[{"introduced":"0"},{"last_affected":"7.0.0-alpha7"}]}]}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"}]}