TROYANOSYVIRUS
Retour aux CVEs

CVE-2022-23134

LOWCISA KEV
3.7

Description

After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step checks and potentially change the configuration of Zabbix Frontend.

Details CVE

Score CVSS v3.13.7
SeveriteLOW
Vecteur CVSSCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
Vecteur d'attaqueNETWORK
ComplexiteHIGH
Privileges requisNONE
Interaction utilisateurNONE
Publie1/13/2022
Derniere modification10/30/2025
Sourcekev
Observations honeypot0

CISA KEV

FournisseurZabbix
ProduitFrontend
Nom vulnerabiliteZabbix Frontend Improper Access Control Vulnerability
Date ajout KEV2022-02-22
Date limite remediation2022-03-08
Utilise dans ransomwareUnknown

Produits affectes

debian:debian_linuxfedoraproject:fedorazabbix:zabbix

Faiblesses (CWE)

CWE-284CWE-287

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.