peter bassill · operator
$ cve CVE-2022-23131 JSON

CVE-2022-23131 KEV

9.1
CRITICAL · CVSS 3.1 · EPSS 95.7% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2022-03-08.

Description

In the case of instances where the SAML SSO authentication is enabled (non-default), session data can be modified by a malicious actor, because a user login stored in the session was not verified. Malicious unauthenticated actor may exploit this issue to escalate privileges and gain admin access to Zabbix Frontend. To perform the attack, SAML authentication is required to be enabled and the actor has to know the username of Zabbix user (or use the guest account, which is disabled by default).

Scoring

CVSS9.1 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
EPSS95.68% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-290
On CISA KEVyes — remediate by 2022-03-08
Public exploitnone known
Published2022-01-13
Last modified2026-06-17

CISA KEV

NameZabbix Frontend Authentication Bypass Vulnerability
Added2022-02-22
Due2022-03-08
Vendor / productZabbix / Frontend
Ransomware usenone reported

Affected (1)

VendorProduct
zabbixzabbix

References

→ the Explorer  ·  watch your stack  ·  NVD