PT-2022-6805 · Zabbix+2 · Zabbix Frontend+3

Alexander Vladishev

+1

·

Published

2022-10-18

·

Updated

2024-10-03

·

CVE-2022-43515

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Zabbix Frontend (affected versions not specified)
Description The issue is related to the incorrect implementation of IP address checking in Zabbix Frontend, which allows an attacker to bypass protection and access the instance using an IP address not listed in the defined range. This could lead to unauthorized access to confidential data, disruption of data integrity, and potential denial of service.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Authorization

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-04799
CVE-2022-43515
DLA-3538-1
DLA-3538-2
DLA-3909-1
SUSE-SU-2022:4477-1
SUSE-SU-2022_4477-1

Affected Products

Astra Linux
Suse
Zabbix
Zabbix Frontend