ZeroHour

CVE-2022-23131

KEVlarge

Authentication Bypass via Unverified SAML Session Data in Zabbix Frontend

CISA: Zabbix Frontend Authentication Bypass Vulnerability

CVSS 3.1
9.8 critical
EPSS
96%p100
Published
()
KEV added
AI analysis

CVE-2022-23131 is a critical (CVSS 9.8) authentication-bypass flaw (CWE-290) in the Zabbix web frontend in which the user login stored in session data is not verified. When SAML SSO authentication is enabled (a non-default configuration), an unauthenticated attacker who can reach the frontend can modify session data to log in as any username they know, including the built-in guest account if it is enabled. By impersonating a known user this way, the attacker escalates privileges and gains admin access to the Zabbix Frontend and the monitoring data and control it provides. Only SAML-enabled deployments are affected, and the attacker must know a valid Zabbix username (or the guest account must be enabled). CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-02-22 alongside a second Zabbix flaw, with reports of Zabbix servers under active attack and a 95.7% EPSS probability of exploitation within 30 days; ransomware use is unknown and no public PoC is catalogued.

What to do: Upgrade Zabbix Frontend to a patched release per the vendor's instructions, as required by CISA's KEV listing; until patched, disable SAML SSO authentication since the bypass requires it, and keep the guest account disabled. Prioritize internet-facing Zabbix frontends and review authentication logs for unauthorized administrator sessions or logins.

Affected
Zabbix Frontend
Estimated exposure
largetens of thousands of internet-exposed Zabbix frontends, of which only the non-default SAML-SSO-enabled subset is directly exploitable — Zabbix is one of the most widely deployed open-source monitoring platforms and public internet scans show tens of thousands of exposed Zabbix frontends, but this flaw requires the non-default SAML SSO configuration, which shrinks the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

In the case of instances where the SAML SSO authentication is enabled (non-default), session data can be modified by a malicious actor, because a user login stored in the session was not verified. Malicious unauthenticated actor may exploit this issue to escalate privileges and gain admin access to Zabbix Frontend. To perform the attack, SAML authentication is required to be enabled and the actor has to know the username of Zabbix user (or use the guest account, which is disabled by default).

CISA Known Exploited Vulnerability
Affected
Zabbix Frontend
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
zabbix
Products
zabbix
Weakness
CWE-290
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news