Impact
Host search functionality in Zabbix’s web interface permits filtering on hidden fields, such as stored IPMI and pre‑shared key credentials. A user with read‑level access can supply a guess for a credential, submit the search request, and examine the returned records to see if the guess matches a stored value. This observation allows the attacker to infer the exact credentials over repeated attempts, eventually revealing sensitive host authentication data. The vulnerability represents an information disclosure flaw (CWE‑204).
Affected Systems
Zabbix, the widely deployed monitoring platform, is affected. The flaw impacts any Zabbix installation that employs the frontend host‑search feature and stores IPMI or PSK credentials. Specific product versions or build numbers are not listed in the advisory; administrators should verify that their deployment includes the affected component before patching.
Risk and Exploitability
With a CVSS score of 5.1, the flaw is considered moderate severity. No EPSS score is available, and the vulnerability is not listed in CISA’s Known Exploited Vulnerabilities catalog. The likely attack vector is via the web interface; an attacker needs authenticated read access and the ability to submit search queries. Because credential guesses are verified through search results, the risk escalates with the number of guesses an attacker can make.
OpenCVE Enrichment