TROYANOSYVIRUS
Back to CVEs

CVE-2022-23134

LOWCISA KEV
3.7

Description

After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step checks and potentially change the configuration of Zabbix Frontend.

CVE Details

CVSS v3.1 Score3.7
SeverityLOW
CVSS VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Attack VectorNETWORK
ComplexityHIGH
Privileges RequiredNONE
User InteractionNONE
Published1/13/2022
Last Modified10/30/2025
Sourcekev
Honeypot Sightings0

CISA KEV

VendorZabbix
ProductFrontend
Vulnerability NameZabbix Frontend Improper Access Control Vulnerability
KEV Date Added2022-02-22
Remediation Due Date2022-03-08
Ransomware UseUnknown

Affected Products

debian:debian_linuxfedoraproject:fedorazabbix:zabbix

Weaknesses (CWE)

CWE-284CWE-287

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.