CVE-2022-23134 is an authentication bypass vulnerability in Zabbix Frontend, affecting various Zabbix versions across Debian and Fedora distributions. It allows unauthenticated users to access and potentially alter Zabbix configuration steps after initial setup. With a CVSS score of 5.3 (MEDIUM), its low attack complexity and network-based vector enable unauthorized configuration changes, though without direct impact on confidentiality or availability. This vulnerability is actively exploited in the wild, as confirmed by its presence in CISA's KEV catalog and high EPSS score, despite a lack of public Metasploit or ExploitDB modules. Community discussion and media coverage indicate significant attention to this threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 5.4.0, <= 5.4.8CPE matchmatch criteria | cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:* | ||
6.0.0CPE matchmatch criteria | cpe:2.3:a:zabbix:zabbix:6.0.0:alpha1:*:*:*:*:*:* | ||
6.0.0CPE matchmatch criteria | cpe:2.3:a:zabbix:zabbix:6.0.0:alpha2:*:*:*:*:*:* | ||
6.0.0CPE matchmatch criteria | cpe:2.3:a:zabbix:zabbix:6.0.0:alpha3:*:*:*:*:*:* | ||
6.0.0CPE matchmatch criteria | cpe:2.3:a:zabbix:zabbix:6.0.0:alpha4:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.