ZeroHour
The Recordpublished ()ingested

CISA: Zabbix servers under attack with recently disclosed vulnerability

highVulnerability exploited in the wildimportance 60CVE-2022-23131CVE-2022-23134CVE-2022-24255

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2022-23131
+1 in the same advisory: …23134
Authentication Bypass via Unverified SAML Session Data in Zabbix Frontend

CVE-2022-23131 is a critical (CVSS 9.8) authentication-bypass flaw (CWE-290) in the Zabbix web frontend in which the user login stored in session data is not verified. When SAML SSO authentication is enabled (a non-default configuration), an unauthenticated attacker who can reach the frontend can modify session data to log in as any username they know, including the built-in guest account if it is enabled. By impersonating a known user this way, the attacker escalates privileges and gains admin access to the Zabbix Frontend and the monitoring data and control it provides. Only SAML-enabled deployments are affected, and the attacker must know a valid Zabbix username (or the guest account must be enabled). CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2022-02-22 alongside a second Zabbix flaw, with reports of Zabbix servers under active attack and a 95.7% EPSS probability of exploitation within 30 days; ransomware use is unknown and no public PoC is catalogued.

Do: Upgrade Zabbix Frontend to a patched release per the vendor's instructions, as required by CISA's KEV listing; until patched, disable SAML SSO authentication since the bypass requires it, and keep the guest account disabled. Prioritize internet-facing Zabbix frontends and review authentication logs for unauthorized administrator sessions or logins.

9.8
group max
96% KEV
  • Zabbix Frontend
largetens of thousands of internet-exposed Zabbix frontends, of which only the non-default SAML-SSO-enabled subset is directly exploitable
CVE-2022-24255
Extensis Portfolio v4.0 was discovered to contain hardcoded credentials which allows attackers to gain administrator privileges.

Extensis Portfolio v4.0 was discovered to contain hardcoded credentials which allows attackers to gain administrator privileges.

NVD description · AI analysis pending
8.81% PoC
  • extensis portfolio
Full article393 words · extracted from therecord.media · click to collapse

The US Cybersecurity Infrastructure and Security Agency has asked federal agencies to patch any Zabbix servers they may be operating after it learned that threat actors have started using two vulnerabilities disclosed last week to take over unpatched systems.

The vulnerabilities references in the CISA alert are tracked as CVE-2022-23131 and CVE-2022-23134, and both were disclosed last week in a write-up from security firm SonarSource.

The first is a bug in how Zabbix stores session data, allowing an attacker to bypass authentication procedures, while the second bug has its root in the incorrect handling of the Zabbix installer files that allows unauthenticated users (attackers) to access some of these resources and re-configure servers.

They impact Zabbix, which is a very popular open-source web-based app that can be used to monitor and receive telemetry from a wide array of IT systems deployed inside large enterprise networks, supporting acquisition from workstations, servers, and cloud resources alike.

In its technical write-up last week, SonarSource described the exploitation of these two bugs as "straightforward," as attackers only had to access a Zabbix's setup.php file to take over a server.

The Zabbix team released updates last week, but as has been the recent trend, threat actors were quick to move to weaponize the disclosed vulnerabilities in the hopes of gaining footholds inside large corporate networks, access they could use to escalate intrusions or sell to other criminal groups.

While CISA has not released details about the current exploitation attempts, proof-of-concept for at least one of the vulnerabilities has been available on GitHub for at least a few days.

According to a Shodan Trends page, there are currently more than 3,800 Zabbix instances connected to the internet, which if left unpatched, are at serious risk of getting hacked.

A day after SonarSource published its Zabbix write-up, fellow security firm White Oak Security published a report detailing a hardcoded backdoor account in Extensis Portfolio, another IT monitoring and management tool. Exploitation of this vulnerability (CVE-2022-24255) has not been observed—yet—but it's just as an attractive target as Zabbix systems and even easier to exploit.

No previous article

No new articles

Catalin Cimpanu

is a cybersecurity reporter who previously worked at ZDNet and Bleeping Computer, where he became a well-known name in the industry for his constant scoops on new vulnerabilities, cyberattacks, and law enforcement actions against hackers.

Text extracted automatically; images, tables and formatting may be missing. Original: https://therecord.media/cisa-zabbix-servers-under-attack-with-recently-disclosed-vulnerability