MEDIUM
CVE-2022-23134
CVSS
5.3
KEV
Description
After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step checks and potentially change the configuration of Zabbix Frontend.
Summary dbcve.org
Zabbix Frontend setup.php contains an access control flaw where certain configuration steps remain accessible to unauthenticated users after the initial setup process completes. This allows attackers to bypass step verification checks and potentially modify frontend configuration settings.
Mitigation
Restrict access to setup.php to authenticated super-administrators only, or disable/remove setup.php after initial configuration is complete. Verify that all setup steps require proper authentication.
Weakness (CWE)
CWE-284
Improper Access Control
CWE-287
Improper Authentication
EPSS Score
95.26%
Probability of exploitation in next 30 days
99.9th percentile
References
https://lists.debian.org/debian-lts-announce/2022/02/msg00008.html
Mailing List, Third Party Advisory
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6SZYHXINBKCY42ITFSNCYE7KCSF33VRA/
Release Notes
https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VB6W556GVXOKUYTASTDGL3AI7S3SJHX7/
Release Notes
https://support.zabbix.com/browse/ZBX-20384
Issue Tracking, Patch, Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-23134
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.