CVE-2022-46768 is an arbitrary file read vulnerability affecting Zabbix Web Service Report Generation and Zabbix Agent2, stemming from improper validation of URL parameters. With a CVSS score of 5.9 (Medium), it allows an unauthenticated attacker to read sensitive files remotely with high confidentiality impact, though high attack complexity is required. Currently, there is no public exploit code available, nor is there evidence of active exploitation or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 6.0.0, <= 6.0.11CPE matchmatch criteria | cpe:2.3:a:zabbix:web_service_report_generation:*:*:*:*:*:*:*:* | ||
>= 6.2.0, <= 6.2.5CPE matchmatch criteria | cpe:2.3:a:zabbix:web_service_report_generation:*:*:*:*:*:*:*:* | ||
< 6.0.12CPE matchmatch criteria | cpe:2.3:a:zabbix:zabbix-agent2:*:*:*:*:*:*:*:* | ||
>= 6.2.0, < 6.2.6CPE matchmatch criteria | cpe:2.3:a:zabbix:zabbix-agent2:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.