Exposição de Zabbix

Miscellaneous
29
score de exposição
6
sites usam
0
em exploração
9
críticos
Análise Vexday

Com 70 CVEs catalogadas, o Zabbix apresenta taxa de exploração ativa abaixo da média geral do catálogo KEV, sem registros confirmados de uso malicioso ativo no momento. No entanto, a ausência de exploração confirmada não elimina o risco: CVE-2024-42327 concentra um escore EPSS de 0,7883, indicando probabilidade elevada de exploração futura segundo modelos preditivos. O tipo de falha mais recorrente é CWE-20 (validação imprópria de entrada), padrão que historicamente facilita encadeamento de vulnerabilidades em plataformas de monitoramento com amplo acesso à infraestrutura. Com 9 CVEs críticas no total e 3 surgidas nos últimos 90 dias, equipes que operam Zabbix em ambientes expostos devem priorizar a aplicação de patches recentes e monitorar ativamente CVE-2024-42327.

CVEs

81 resultados
CVE-2024-36461CRITICALDirect access to memory pointers within the JS engine for modificationEPSS 0.8%CVE-2023-32728MEDIUMCode injection in zabbix_agent2 smart.disk.get caused by smartctl pluginEPSS 0.8%CVE-2023-29453CRITICALAgent 2 package are built with Go version affected by CVE-2023-24538EPSS 0.8%CVE-2024-22119MEDIUMStored XSS in graph items select formEPSS 0.7%CVE-2024-36466HIGHUnauthenticated Zabbix frontend takeover when SSO is being usedEPSS 0.7%CVE-2024-36467HIGHAuthentication privilege escalation via user groups due to missing authorization checksEPSS 0.7%CVE-2023-32722CRITICALStack-buffer Overflow in library module zbxjsonEPSS 0.7%CVE-2023-32726LOWPossible buffer overread from reading DNS responsesEPSS 0.7%CVE-2024-42333LOWHeap buffer over-readEPSS 0.6%CVE-2024-42332LOWNew line injection in Zabbix SNMP trapsEPSS 0.6%CVE-2024-36460HIGHFront-end audit log shows passwords in plaintextEPSS 0.6%CVE-2023-29455MEDIUMReflected XSS in several fields of graph formEPSS 0.6%CVE-2023-32721HIGHStored XSS in Maps elementEPSS 0.6%CVE-2023-32724CRITICALJavaScript engine memory pointers are directly available for Zabbix users for modificationEPSS 0.6%CVE-2024-22114MEDIUMSystem Information Widget in Global View Dashboard exposes information about Hosts to Users without PermissionEPSS 0.6%CVE-2023-29454MEDIUMPersistent XSS in the user formEPSS 0.6%CVE-2024-22123LOWZabbix Arbitrary File ReadEPSS 0.6%CVE-2023-29457MEDIUMInsufficient validation of Action form input fieldsEPSS 0.6%CVE-2023-32723HIGHInefficient permission check in class CControllerAuthenticationUpdateEPSS 0.6%CVE-2023-29456MEDIUMInefficient URL schema validationEPSS 0.6%