V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2022-23131
DEB
Critical KEVConfirmedExploit available

In the case of instances where the SAML SSO authentication is enabled (non-default), session data can be modified by a malicious actor, bec…

CVSS
9.8
Critical
EPSS
0.96
p99
Published
2022-01-01
Updated
2022-02-22
Description

In the case of instances where the SAML SSO authentication is enabled (non-default), session data can be modified by a malicious actor, because a user login stored in the session was not verified. Malicious unauthenticated actor may exploit this issue to escalate privileges and gain admin access to Zabbix Frontend. To perform the attack, SAML authentication is required to be enabled and the actor has to know the username of Zabbix user (or use the guest account, which is disabled by default).

Tags · CWE
KEVPre-auth
CWE-290
CAPEC-21
CAPEC-22
CAPEC-59
CAPEC-60
CAPEC-94
CAPEC-459
CAPEC-461
CAPEC-473
CAPEC-476
CAPEC-667
Affected products
Zabbix 5.4.0–5.4.8Zabbix
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
2022-01-01
Published
2022-02-22
Added to KEV
2022-02-22
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.957 · p99
Known exploited (KEV)
Yes
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-473 · CWE-290
└ via CAPEC-21 · CWE-290
└ via CAPEC-60 · CWE-290
└ via CAPEC-21 · CWE-290
└ via CAPEC-21 · CWE-290
└ via CAPEC-60 · CWE-290
└ via CAPEC-473 · CWE-290
└ via CAPEC-94 · CWE-290
Known exploits — Сканер-ВС
CVE-2022-23131
cisa · https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Enterprise
Affected products
ProductVendorStatus
zabbixExploited
zabbixExploited
zabbixExploited
zabbixExploited
zabbixExploited
zabbixExploited
zabbixExploited
zabbixExploited
zabbixExploited
zabbixExploited
zabbixExploited
zabbix*Exploited
Source databases
DEB
CVE
UBU
Related vulnerabilities