POLICY-OTHER --
POLICY-OTHER Zabbix Frontend setup reconfiguration attempt
This rule looks for requests to the Zabbix "/setup.php" endpoint that attempt to reconfigure the Zabbix database settings. Malicious actors, if successful, can utilize this to get administrative access to the Zabbix frontend.
This rule fires on attempts to reconfigure Zabbix applications.
Attacks/Scans seen in the wild
Known false positives, with the described conditions
This rule fires on all requests attempting to reconfigure the Zabbix server.
Cisco Talos Intelligence Group
Rule Categories::Server::Web Applications
Rule Categories::Policy::Other
MITRE::ATT&CK Framework::Enterprise::Initial Access::Exploit Public-Facing Application
N/A
Not Applicable
CVE-2022-23134 |
Loading description
|