Zabbix Frontend provides a feature that allows admins to maintain the installation and ensure that only certain IP addresses can access it. In this way, any user will not be able to access the Zabbix Frontend while it is being maintained and possible sensitive data will be prevented from being disclosed. An attacker can bypass this protection and access the instance using IP address not listed in the defined range.
Advisories
Source ID Title
Debian DLA Debian DLA DLA-3538-1 zabbix security update
Debian DLA Debian DLA DLA-3909-1 zabbix security update
EUVD EUVD EUVD-2022-46513 Zabbix Frontend provides a feature that allows admins to maintain the installation and ensure that only certain IP addresses can access it. In this way, any user will not be able to access the Zabbix Frontend while it is being maintained and possible sensitive data will be prevented from being disclosed. An attacker can bypass this protection and access the instance using IP address not listed in the defined range.
Fixes

Solution

To remediate this vulnerability, apply the updates listed in the 'Unaffected' section to appropriate products or use the workaround


Workaround

If an immediate update is not possible, limit network access to Zabbix Frontend during the maintenance window.

History

Tue, 22 Apr 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Zabbix

Published:

Updated: 2025-04-22T17:58:50.632Z

Reserved: 2022-10-19T00:00:00.000Z

Link: CVE-2022-43515

cve-icon Vulnrichment

Updated: 2024-08-03T13:32:59.684Z

cve-icon NVD

Status : Modified

Published: 2022-12-05T19:15:10.363

Modified: 2024-11-21T07:26:40.877

Link: CVE-2022-43515

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.