login
quiescence.eu
Aller au contenu

CVE-2022-23134

Zabbix Frontend Improper Access Control Vulnerability

n/a
CVSS
84.7%
EPSS (exploit prob.)
99.7%
EPSS percentile
Yes
Actively exploited
No
Ransomware use
2022-02-22
Added

Summary

Malicious actors can pass step checks and potentially change the configuration of Zabbix Frontend.

Affected software

Vendor: Zabbix  ·  Product: Frontend

Weakness types (CWE):

CWE-284

What to do

This vulnerability appears in CISA's Known Exploited Vulnerabilities catalog, meaning it is being exploited in the wild. Prioritize patching affected systems and verify exposure across your estate.

Related vulnerabilities in Zabbix

CVENameEPSSExploited
CVE-2022-23131 Zabbix Frontend Authentication Bypass Vulnerability 95.7% Yes

Is your domain exposed?

Run a free, instant security report for any domain — exposure score, email auth, TLS and breach metadata.

Get your free report

All information is aggregated from public sources for awareness only and does not constitute an accusation or a security assessment. No personal data or credentials are published.