Record summary

CVE-2022-43515 has a selected CVSS score of 5.3 (medium).

Description

Zabbix Frontend provides a feature that allows admins to maintain the installation and ensure that only certain IP addresses can access it. In this way, any user will not be able to access the Zabbix Frontend while it is being maintained and possible sensitive data will be prevented from being disclosed. An attacker can bypass this protection and access the instance using IP address not listed in the defined range.

Description source: CVE List

Exploitation context

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 22, 2025 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus
CVE List4.0.0-4.0.44affected
5.0.0-5.0.29affected
6.0.0-6.0.9affected
6.2.0-6.2.4affected
5.0.30rc1unaffected
6.0.11rc1unaffected
6.2.5rc1unaffected

References

5