ZeroHour

CVE-2022-23134

KEVlarge

Unauthenticated Improper Access Control in Zabbix Frontend Setup Actively Exploited

CISA: Zabbix Frontend Improper Access Control Vulnerability

CVSS 3.1
5.3 medium
EPSS
85%p100
Published
()
KEV added
AI analysis

CVE-2022-23134 is an improper access control flaw (CWE-284/CWE-287) in the Zabbix Frontend in which, once the initial setup has been completed, some steps of the setup.php file remain reachable not only by super-administrators but also by unauthenticated users. An attacker triggers it by sending crafted requests directly to setup.php over the network (network vector, low complexity, no privileges or user interaction required), passing the step checks that should require administrative access. If successful, the attacker can potentially change the Zabbix Frontend configuration, which could alter the monitoring setup or be chained toward further compromise; the CVSS 3.1 impact is limited to integrity (5.3, medium). Anyone running an affected Zabbix Frontend is exposed, including packages distributed via Fedora and Debian, which are listed as affected products. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities Catalog on 2022-02-22 and issued alerts about attacks on Zabbix servers, no public PoC is known, EPSS is very high at 84.7% (100th percentile), and ransomware use is unknown.

What to do: Apply updates per vendor instructions (CISA's required action), installing a patched Zabbix release for your distribution or upstream channel. Until patched, restrict network access to Zabbix Frontend instances (especially setup.php) to trusted users via firewall or access-control rules, and review exposed frontends for unexpected configuration changes. Prioritize internet-facing Zabbix servers given the active exploitation and high EPSS score.

Affected
Zabbix Frontend
Fedora
Debian Linux
Estimated exposure
large≈10,000–50,000 internet-exposed Zabbix frontends (tens of thousands of exposed instances), with a substantially larger installed base on internal networks — Zabbix is a widely deployed open-source network monitoring platform and public internet-wide scan counts around disclosure showed tens of thousands of Zabbix frontends reachable from the internet, while many more run on internal networks.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step checks and potentially change the configuration of Zabbix Frontend.

CISA Known Exploited Vulnerability
Affected
Zabbix Frontend
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
zabbixfedoraprojectdebian
Products
zabbix, fedora, debian linux
Weakness
CWE-284, CWE-287
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

In the news