CVE-2022-23134

Confirmed PUBLISHED

Possible view of the setup pages by unauthenticated users if config file already exists

Zabbix · Frontend
Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
3.7 Low

At a Glance

After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step checks and potentially change the configuration of Zabbix Frontend.

nuclei_scanner cisa php
CVE Published
Jan 13, 2022
Exploitation Reported
Feb 22, 2022
CVSS
3.7 Low
EPSS
Remote No user interaction Unauthenticated

Affected Versions

Vendor Product Version Status
Zabbix
Frontend

5.4.0 - 5.4.8

Affected
Zabbix
Frontend

5.4.9 to < 5.4.9*

Unaffected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.