PT-2022-6820 · Zabbix+1 · Zabbix+1

Alexey Mitrofanov

·

Published

2022-09-26

·

Updated

2023-08-23

·

CVE-2022-46768

CVSS v3.1

5.9

Medium

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Zabbix (affected versions not specified)
Description A security issue exists in Zabbix Web Service Report Generation, which listens on port 10053. The service lacks proper validation for URL parameters before reading files, allowing for arbitrary file read. This could enable a remote attacker to access confidential data.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

BDU:2023-04815
CVE-2022-46768
ZDI-23-1168

Affected Products

Astra Linux
Zabbix