Junglewise Threat Intelligence

CVE-2022-23134: Zabbix Frontend Improper Access Control Vulnerability

CVE-2022-23134 · Severity: critical · CVSS 5.3 · Exploited in the wild · Published 2022-02-22

Technologies: Zabbix Frontend. Vendors: Zabbix.

Executive brief

An improper access control vulnerability in Zabbix Frontend allows unauthenticated users to access certain steps of the setup.php file after the initial setup process. Malicious actors can bypass step checks to potentially modify the configuration of the Zabbix Frontend.

Affected products

  • Zabbix Frontend

Timeline

  • 2022-02-22: disclosed
  • 2022-02-22: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats