Low severity3.7CISA KEVNVD Advisory· Published Jan 13, 2022· Updated Jun 17, 2026
CVE-2022-23134
CVE-2022-23134
Description
After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step checks and potentially change the configuration of Zabbix Frontend.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
15cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:*+ 9 more
- cpe:2.3:a:zabbix:zabbix:*:*:*:*:*:*:*:*range: >=5.4.0,<=5.4.8
- cpe:2.3:a:zabbix:zabbix:6.0.0:alpha1:*:*:*:*:*:*
- cpe:2.3:a:zabbix:zabbix:6.0.0:alpha2:*:*:*:*:*:*
- cpe:2.3:a:zabbix:zabbix:6.0.0:alpha3:*:*:*:*:*:*
- cpe:2.3:a:zabbix:zabbix:6.0.0:alpha4:*:*:*:*:*:*
- cpe:2.3:a:zabbix:zabbix:6.0.0:alpha5:*:*:*:*:*:*
- cpe:2.3:a:zabbix:zabbix:6.0.0:alpha6:*:*:*:*:*:*
- cpe:2.3:a:zabbix:zabbix:6.0.0:alpha7:*:*:*:*:*:*
- cpe:2.3:a:zabbix:zabbix:6.0.0:beta1:*:*:*:*:*:*
- (no CPE)
cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:o:fedoraproject:fedora:34:*:*:*:*:*:*:*
- cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*
- Zabbix/Frontendv5Range: 5.4.0 - 5.4.8
Patches
Vulnerability mechanics
References
5- support.zabbix.com/browse/ZBX-20384nvdIssue TrackingPatchVendor Advisory
- lists.debian.org/debian-lts-announce/2022/02/msg00008.htmlnvdMailing ListThird Party Advisory
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/6SZYHXINBKCY42ITFSNCYE7KCSF33VRA/nvdRelease Notes
- lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/VB6W556GVXOKUYTASTDGL3AI7S3SJHX7/nvdRelease Notes
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
0No linked articles in our index yet.