Rule Category

POLICY-OTHER --

Alert Message

POLICY-OTHER Zabbix Frontend setup reconfiguration attempt

Rule Explanation

This rule looks for requests to the Zabbix "/setup.php" endpoint that attempt to reconfigure the Zabbix database settings. Malicious actors, if successful, can utilize this to get administrative access to the Zabbix frontend.

What To Look For

This rule fires on attempts to reconfigure Zabbix applications.

Known Usage

Attacks/Scans seen in the wild

False Positives

Known false positives, with the described conditions

This rule fires on all requests attempting to reconfigure the Zabbix server.

Contributors

Cisco Talos Intelligence Group

Rule Groups

Rule Categories::Server::Web Applications

Rule Categories::Policy::Other

MITRE::ATT&CK Framework::Enterprise::Initial Access::Exploit Public-Facing Application

CVE

Additional Links

Rule Vulnerability

N/A

Not Applicable

CVE Additional Information

This product uses data from the NVD API but is not endorsed or certified by the NVD.
CVE-2022-23134
Loading description