Impact
An unauthenticated attacker can craft requests to the Frontend popup.testtriggerexpr action, causing the web server to perform expensive expression evaluations and generate disproportionate CPU load. The resulting resource exhaustion can render the Zabbix frontend unresponsive, effectively denying legitimate users access. The weakness is classified as CWE‑405, indicating insufficient validation of user‑supplied input before processing.
Affected Systems
The vulnerability affects the Zabbix web frontend. Vendor: Zabbix. No specific version information is provided in the data, so all releases prior to the fixed version are potentially affected.
Risk and Exploitability
The CVSS score of 5.3 places the issue in the moderate severity range. EPSS data is unavailable, and the vulnerability is not listed in CISA KEV, suggesting a lower current exploitation likelihood. However, the attack vector is inferred to be remote, unauthenticated, and requires only the ability to send crafted HTTP requests to the exposed endpoint. Deployments with wide internet exposure and no request limiting could be at higher risk.
OpenCVE Enrichment