S4E just found a high top 10 tcp port service scan
critical·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-23131 Scanner

Detects 'Authentication Bypass' vulnerability in Zabbix affects v. 5.4.0 - 5.4.8.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
3k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2022-23131
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

In the case of instances where the SAML SSO authentication is enabled (non-default), session data can be modified by a malicious actor, because a user login stored in the session was not verified. Malicious unauthenticated actor may exploit this issue to escalate privileges and gain admin access to Zabbix Frontend. To perform the attack, SAML authentication is required to be enabled and the actor has to know the username of Zabbix user (or use the guest account, which is disabled by default).

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Frontendby Zabbix
5.4.0 - 5.4.8
Updated Aug 22, 2026View on NVD →
Detail

Zabbix is an open-source monitoring software that is used to track the performance and availability of network devices, servers, and applications. Its primary purpose is to provide users with a comprehensive overview of their IT infrastructure in real-time. In addition, it allows for alerting and reporting mechanisms to be configured so that administrators can be notified of potential problems before they escalate.

The CVE-2022-23131 vulnerability was detected in Zabbix, specifically in instances where SAML SSO authentication is enabled. This vulnerability allows a malicious user to modify session data by exploiting the fact that a user login stored in the session was not verified. This means that a malicious user could potentially escalate their privileges and gain admin access to Zabbix Frontend. To perform the attack, SAML authentication must be enabled, and the attacker must either know the username of a Zabbix user or use the guest account (which is disabled by default).

If the CVE-2022-23131 vulnerability is exploited, it can lead to a range of serious consequences. A malicious actor could gain access to sensitive data and control functions in Zabbix Frontend, allowing them to manipulate network devices, servers, and applications at will. This could result in system downtime, data exfiltration, and other severe security breaches that could harm an organization's reputation and bottom line.

It is important for organizations to take prompt and decisive action to protect their digital assets from threats like the CVE-2022-23131 vulnerability. By utilizing the pro features of the s4e.io platform, readers can easily and quickly learn about vulnerabilities in their digital assets and take the necessary steps to secure them. This platform offers comprehensive vulnerability scanning, reporting, and management tools that help organizations stay ahead of threats and maintain a robust security posture.

 

REFERENCES

Solution Advice

To protect against this vulnerability, there are several precautions that organizations can take, including:

  • Disable SAML SSO authentication if it is not needed
  • Ensure that all users have strong, unique passwords
  • Implement multi-factor authentication
  • Regularly monitor and audit access logs

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.