S4E just found a high-severity finding from ssl sweet32 vulnerability checker
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
medium·Product Based Web Vulnerabilities·Updated Jan 3, 2024

CVE-2022-23134 Scanner

Detects 'Improper Access Control' vulnerability in Zabbix affects v. from 5.4.0 to 5.4.8.

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsurl
CostFree
2.8k
Times Used
continuous scan runs
5.5k
Continuously Checked
assets under CS
1
Vulnerabilities Found
confirmed findings
References
🔴
CISA Known Exploited Vulnerability
This CVE is actively exploited in the wild. CISA mandates federal agencies to patch immediately.
CVECVE-2022-23134
5.3
CVSSlow
Exploitable remotely over the internet · no authentication required.

After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step checks and potentially change the configuration of Zabbix Frontend.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
Frontendby Zabbix
5.4.0 - 5.4.8
Updated Aug 22, 2026View on NVD →
Detail

Zabbix is an open-source monitoring tool designed to monitor servers, applications, network devices, and services. It is widely used in many industries such as IT, finance, healthcare, and more. Zabbix provides an efficient solution for tracking performance metrics, troubleshooting issues and receiving alerts when issues arise. The tool has a web-based interface which enables users to set up and manage monitoring systems easily.

One of the vulnerabilities that have been detected in Zabbix is CVE-2022-23134. This vulnerability allows unauthenticated users to access some of the steps of the setup.php file, which should only be accessible by super-administrators. A malicious actor can exploit this vulnerability to change the configuration of Zabbix Frontend, potentially causing damage to the monitored systems.

When exploited, CVE-2022-23134 can lead to unauthorized access to sensitive data and changes in monitoring configurations. This can result in the loss of valuable information, equipment damage, and even the complete shutdown of critical services. Therefore, it is crucial to take precautions to prevent this vulnerability from being exploited.

Thanks to the professional features of the s4e.io platform, readers of this article can easily and quickly learn about vulnerabilities in their digital assets. The platform provides in-depth vulnerability scanning, reporting and management solutions for organizations of all sizes. By utilizing the platform's various security tools, organizations can secure their digital assets and mitigate potential cyber attacks.

 

REFERENCES

Solution Advice

There are several precautions that can be taken to protect against CVE-2022-23134, such as:

  • Ensure that the setup.php file is only accessible by super-administrators
  • Implement two-factor authentication for administrators
  • Keep your Zabbix installation up-to-date with the latest security patches
  • Restrict network access to Zabbix instances
  • Audit all access to Zabbix instances and review them regularly

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2022-23134 scanner - Improper Access Control vulnerability in Zabbix | S4E