CVE-2022-23131
KEVlargeAuthentication Bypass via Unverified SAML Session Data in Zabbix Frontend
CISA: Zabbix Frontend Authentication Bypass Vulnerability
CVE-2022-23131 is a critical (CVSS 9.8) authentication-bypass flaw (CWE-290) in the Zabbix web frontend in which the user login stored in session data is not verified. When SAML SSO authentication is enabled (a non-default configuration), an unauthenticated attacker who can reach the frontend can modify session data to log in as any username they know, including the built-in guest account if it is enabled. By impersonating a known user this way, the attacker escalates privileges and gains admin access to the Zabbix Frontend and the monitoring data and control it provides. Only SAML-enabled deployments are affected, and the attacker must know a valid Zabbix username (or the guest account must be enabled). CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-02-22 alongside a second Zabbix flaw, with reports of Zabbix servers under active attack and a 95.7% EPSS probability of exploitation within 30 days; ransomware use is unknown and no public PoC is catalogued.
What to do: Upgrade Zabbix Frontend to a patched release per the vendor's instructions, as required by CISA's KEV listing; until patched, disable SAML SSO authentication since the bypass requires it, and keep the guest account disabled. Prioritize internet-facing Zabbix frontends and review authentication logs for unauthorized administrator sessions or logins.
| Zabbix Frontend | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
In the case of instances where the SAML SSO authentication is enabled (non-default), session data can be modified by a malicious actor, because a user login stored in the session was not verified. Malicious unauthenticated actor may exploit this issue to escalate privileges and gain admin access to Zabbix Frontend. To perform the attack, SAML authentication is required to be enabled and the actor has to know the username of Zabbix user (or use the guest account, which is disabled by default).
- Affected
- Zabbix Frontend
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- zabbix
- Products
- zabbix
- Weakness
- CWE-290
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H