TROYANOSYVIRUS
Zuruck zu CVEs

CVE-2022-23134

LOWCISA KEV
3.7

Beschreibung

After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step checks and potentially change the configuration of Zabbix Frontend.

CVE Details

CVSS v3.1 Bewertung3.7
SchweregradLOW
CVSS VektorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
AngriffsvektorNETWORK
KomplexitatHIGH
Erforderliche PrivilegienNONE
BenutzerinteraktionNONE
Veroffentlicht1/13/2022
Zuletzt geandert10/30/2025
Quellekev
Honeypot-Sichtungen0

CISA KEV

HerstellerZabbix
ProduktFrontend
SchwachstellennameZabbix Frontend Improper Access Control Vulnerability
KEV Aufnahmedatum2022-02-22
Behebungsfrist2022-03-08
Ransomware-NutzungUnknown

Betroffene Produkte

debian:debian_linuxfedoraproject:fedorazabbix:zabbix

Schwachen (CWE)

CWE-284CWE-287

IOC Korrelationen

Keine Korrelationen erfasst

This product uses data from the NVD API but is not endorsed or certified by the NVD.