⚠ Actively exploited
Added to CISA KEV on 2022-02-22. Federal agencies required to patch by 2022-03-08. Required action: Apply updates per vendor instructions..

CVE-2022-23131Authentication Bypass by Spoofing in Zabbix

Severity
9.8CRITICALNVD
CNA9.1VulnCheck9.1
EPSS
94.0%
top 0.10%
CISA KEV
KEV
Added 2022-02-22
Due 2022-03-08
Exploit
Exploited in wild
Active exploitation observed
Affected products
Timeline
PublishedJan 13
KEV addedFeb 22
Latest updateMar 2
KEV dueMar 8
CISA Required Action: Apply updates per vendor instructions.

Description

In the case of instances where the SAML SSO authentication is enabled (non-default), session data can be modified by a malicious actor, because a user login stored in the session was not verified. Malicious unauthenticated actor may exploit this issue to escalate privileges and gain admin access to Zabbix Frontend. To perform the attack, SAML authentication is required to be enabled and the actor has to know the username of Zabbix user (or use the guest account, which is disabled by default).

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

CVEListV5zabbix/frontend5.4.0 - 5.4.8
NVDzabbix/zabbix5.4.05.4.8+1

Patches

🔴Vulnerability Details

3
GHSA
GHSA-4g73-3mxf-j47w: In the case of instances where the SAML SSO authentication is enabled (non-default), session data can be modified by a malicious actor, because a user2022-01-14
CVEList
Unsafe client-side session storage leading to authentication bypass/instance takeover via Zabbix Frontend with configured SAML2022-01-13
VulnCheck
Zabbix Frontend Authentication Bypass Vulnerability2022

💥Exploits & PoCs

1
Nuclei
Zabbix - SAML SSO Authentication Bypass

🔍Detection Rules

3
Suricata
ET EXPLOIT Zabbix v5.4.0 - 5.4.8 SSO/SALM Auth Bypass (CVE-2022-23131) M22022-03-02
Suricata
ET EXPLOIT Zabbix v5.4.0 - 5.4.8 SSO/SALM Auth Bypass (CVE-2022-23131) M12022-03-02
Suricata
ET EXPLOIT Zabbix v5.4.0 - 5.4.8 SSO/SALM Auth Bypass (CVE-2022-23131) M32022-03-02

📋Vendor Advisories

2
CISA
Zabbix Frontend Authentication Bypass Vulnerability2022-02-22
Debian
CVE-2022-23131: zabbix - In the case of instances where the SAML SSO authentication is enabled (non-defau...2022
CVE-2022-23131 — Authentication Bypass by Spoofing | cvebase