HTTP: Zabbix Server Arbitrary File Read

This signature detects attempts to exploit a known vulnerability against Zabbix Server. A successful attack can lead to sensitive information disclosure.

Extended Description

Arbitrary file read vulnerability exists in Zabbix Web Service Report Generation, which listens on the port 10053. The service does not have proper validation for URL parameters before reading the files.

Affected Products

Zabbix web_service_report_generation

References

CVE: CVE-2022-46768

Short Name
HTTP:CTS:ZABBIX-SRVR-INFO-DIS
Severity
Minor
Recommended
False
Recommended Action
Drop
Category
HTTP
Keywords
Arbitrary CVE-2022-46768 File Read Server Zabbix
Release Date
02/02/2023
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3693
False Positive
Unknown
Vendors

Zabbix

Found a potential security threat?