Impact
The Zabbix API host.get action can be abused by authenticated users to read a host’s pre‑shared key (PSK). Exposure of the PSK undermines data integrity, allowing an attacker to forge or tamper with encrypted traffic to the monitored host, potentially corrupting configuration or metrics data. The weakness is an information exposure flaw (CWE‑203).
Affected Systems
Zabbix products are affected. Specific product names are ‘Zabbix’ as identified by the CNA. No version details are provided in the advisory, so any Zabbix installation that exposes the host.get API to authenticated users may be vulnerable.
Risk and Exploitability
The CVSS score of 6.0 indicates a medium severity, and the EPSS score is not available. The vulnerability is not listed in CISA KEV, suggesting it is not a known widely‑used exploit. The attack requires valid authentication to the Zabbix API, so the risk depends on how strictly API credentials are protected. If an attacker succeeds, they can compromise data integrity of monitored hosts but remote code execution is not directly supported by the flaw.
OpenCVE Enrichment