CVE-2022-23134
KEVlargeUnauthenticated Improper Access Control in Zabbix Frontend Setup Actively Exploited
CISA: Zabbix Frontend Improper Access Control Vulnerability
CVE-2022-23134 is an improper access control flaw (CWE-284/CWE-287) in the Zabbix Frontend in which, once the initial setup has been completed, some steps of the setup.php file remain reachable not only by super-administrators but also by unauthenticated users. An attacker triggers it by sending crafted requests directly to setup.php over the network (network vector, low complexity, no privileges or user interaction required), passing the step checks that should require administrative access. If successful, the attacker can potentially change the Zabbix Frontend configuration, which could alter the monitoring setup or be chained toward further compromise; the CVSS 3.1 impact is limited to integrity (5.3, medium). Anyone running an affected Zabbix Frontend is exposed, including packages distributed via Fedora and Debian, which are listed as affected products. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities Catalog on 2022-02-22 and issued alerts about attacks on Zabbix servers, no public PoC is known, EPSS is very high at 84.7% (100th percentile), and ransomware use is unknown.
What to do: Apply updates per vendor instructions (CISA's required action), installing a patched Zabbix release for your distribution or upstream channel. Until patched, restrict network access to Zabbix Frontend instances (especially setup.php) to trusted users via firewall or access-control rules, and review exposed frontends for unexpected configuration changes. Prioritize internet-facing Zabbix servers given the active exploitation and high EPSS score.
| Zabbix Frontend | — |
| Fedora | — |
| Debian Linux | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step checks and potentially change the configuration of Zabbix Frontend.
- Affected
- Zabbix Frontend
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- zabbixfedoraprojectdebian
- Products
- zabbix, fedora, debian linux
- Weakness
- CWE-284, CWE-287
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N