Zabbix User Enumeration Vulnerability via Timing Attack

Vulnerability

A timing attack vulnerability has been identified in the Zabbix frontend login form and API, allowing for user enumeration. The issue arises because the execution time for an unsuccessful login varies depending on whether a non-existing username or an existing one is used. This discrepancy can be exploited by someone with access to the Zabbix frontend or API to infer the existence of usernames based on the timing of login attempts.

Impact

Exploitation of this vulnerability allows for user enumeration, where an attacker can determine which usernames are valid based on the response times during the login process.

Remediation

Users can upgrade to Zabbix versions 5.0.46rc1, 6.0.38rc1, 7.0.9rc1, or 7.2.3rc1 to address this vulnerability.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
6.2
impact
0.6
exploitability
7.4
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.