EXPOSURES › CVE-2022-23134
CVE-2022-23134
HIGH ⌖ ON CISA KEV · EXPLOITEDZabbix Frontend improper access control allowed attackers to bypass step checks and alter system configuration.
The Zabbix Frontend suffered from an improper access control flaw that let malicious actors bypass security step checks and modify system configurations. This failure impacts DIB organizations relying on Zabbix for monitoring, as attackers could alter monitoring data or disable alerts, leading to blind spots during incidents. Organizations must ensure Zabbix packages are upgraded to patched versions that restore proper access controls.
Shame score — A known access control flaw in a widely deployed monitoring tool that was actively exploited in the KEV catalog, indicating negligent patching and avoidable exposure.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Malicious actors can pass step checks and potentially change the configuration of Zabbix Frontend.