CVE-2022-23131 KEV
9.1
CRITICAL · CVSS 3.1 · EPSS 95.7% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2022-03-08.
Description
In the case of instances where the SAML SSO authentication is enabled (non-default), session data can be modified by a malicious actor, because a user login stored in the session was not verified. Malicious unauthenticated actor may exploit this issue to escalate privileges and gain admin access to Zabbix Frontend. To perform the attack, SAML authentication is required to be enabled and the actor has to know the username of Zabbix user (or use the guest account, which is disabled by default).
Scoring
| CVSS | 9.1 (CRITICAL, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
| EPSS | 95.68% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-290 |
| On CISA KEV | yes — remediate by 2022-03-08 |
| Public exploit | none known |
| Published | 2022-01-13 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | Zabbix Frontend Authentication Bypass Vulnerability |
|---|---|
| Added | 2022-02-22 |
| Due | 2022-03-08 |
| Vendor / product | Zabbix / Frontend |
| Ransomware use | none reported |
Affected (1)
| Vendor | Product |
|---|---|
| zabbix | zabbix |
References
→ the Explorer · watch your stack · NVD