ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

CISA Alerts on Actively Exploited Flaws in Zabbix Network Monitoring Platform

criticalExploit / PoC exploited in the wildimportance 60CVE-2022-23131CVE-2022-23134

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-23131
+1 in the same advisory: …23134
Authentication Bypass via Unverified SAML Session Data in Zabbix Frontend

CVE-2022-23131 is a critical (CVSS 9.8) authentication-bypass flaw (CWE-290) in the Zabbix web frontend in which the user login stored in session data is not verified. When SAML SSO authentication is enabled (a non-default configuration), an unauthenticated attacker who can reach the frontend can modify session data to log in as any username they know, including the built-in guest account if it is enabled. By impersonating a known user this way, the attacker escalates privileges and gains admin access to the Zabbix Frontend and the monitoring data and control it provides. Only SAML-enabled deployments are affected, and the attacker must know a valid Zabbix username (or the guest account must be enabled). CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-02-22 alongside a second Zabbix flaw, with reports of Zabbix servers under active attack and a 95.7% EPSS probability of exploitation within 30 days; ransomware use is unknown and no public PoC is catalogued.

Do: Upgrade Zabbix Frontend to a patched release per the vendor's instructions, as required by CISA's KEV listing; until patched, disable SAML SSO authentication since the bypass requires it, and keep the guest account disabled. Prioritize internet-facing Zabbix frontends and review authentication logs for unauthorized administrator sessions or logins.

9.8
group max
96% KEV
  • Zabbix Frontend
largetens of thousands of internet-exposed Zabbix frontends, of which only the non-default SAML-SSO-enabled subset is directly exploitable
Full article260 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananFeb 24, 2022

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has warned of active exploitation of two security flaws impacting Zabbix open-source enterprise monitoring platform, adding them to its Known Exploited Vulnerabilities Catalog.

On top of that, CISA is also recommending that Federal Civilian Executive Branch (FCEB) agencies patch all systems against the vulnerabilities by March 8, 2022 to reduce their exposure to potential cyberattacks.

Tracked as CVE-2022-23131 (CVSS score: 9.8) and CVE-2022-23134 (CVSS score: 5.3), the shortcomings could lead to the compromise of complete networks, enabling a malicious unauthenticated actor to escalate privileges and gain admin access to the Zabbix Frontend as well as make configuration changes.

Thomas Chauchefoin from SonarSource has been credited with discovering and reporting the two flaws, which affect Zabbix Web Frontend versions up to and including 5.4.8, 5.0.18 and 4.0.36. The issues have since been addressed in versions 5.4.9, 5.0.9 and 4.0.37 shipped late December 2021.

Both the flaws are the result of what the company calls "unsafe session storage," allowing attackers to bypass authentication and execute arbitrary code. It's, however, worth pointing out that the flaws only impact instances where Security Assertion Markup Language (SAML) Single sign-on (SSO) authentication is enabled.

"Always provide access to sensible services with extended internal accesses (e.g., orchestration, monitoring) over VPNs or a restricted set of IP addresses, harden filesystem permissions to prevent unintended changes, remove setup scripts, etc.," Chauchefoin said.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2022/02/cisa-alerts-on-actively-exploited-flaws.html