Skip to content
COOEY

EXPOSURES › CVE-2022-23134

CVE-2022-23134

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-02-22 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2022-23134 ↗
⌖ EXPLOITED IN THE WILD SHAME 65/100 exploited-in-wildunpatched

Zabbix Frontend improper access control allowed attackers to bypass step checks and alter system configuration.

The Zabbix Frontend suffered from an improper access control flaw that let malicious actors bypass security step checks and modify system configurations. This failure impacts DIB organizations relying on Zabbix for monitoring, as attackers could alter monitoring data or disable alerts, leading to blind spots during incidents. Organizations must ensure Zabbix packages are upgraded to patched versions that restore proper access controls.

Shame score — A known access control flaw in a widely deployed monitoring tool that was actively exploited in the KEV catalog, indicating negligent patching and avoidable exposure.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Malicious actors can pass step checks and potentially change the configuration of Zabbix Frontend.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.