Impact
A flaw in the Zabbix Server/Proxy allows specially crafted binary items that contain null byte input to trigger a crash of the server process, causing a loss of availability for the monitoring system. The weakness is categorized as an out‑of‑bounds write (CWE-787) and can lead to denial of service if an attacker can supply the vulnerable payload to a monitored item.
Affected Systems
Deployments of Zabbix Server or Proxy that use MySQL or MariaDB as the backend database are affected; the specific fixed versions are not listed in the public data for this CVE.
Risk and Exploitability
The CVSS score of 2.3 indicates low overall severity, and there is no EPSS data or KEV listing for this issue. The likely attack vector involves the delivery of the payload through a binary item configured to collect data from an untrusted source. Although the risk of exploitation is low, any successful crash would interrupt monitoring and alerting services, impacting availability.
OpenCVE Enrichment