CVE-2022-43516: Zabbix Agent installer adds “allow all TCP any any” firewall rule
A Firewall Rule which allows all incoming TCP connections to all programs from any source and to all ports is created in Windows Firewall after Zabbix agent installation (MSI)
Affected Software
Remediation
Patch Available
Information
Event History
Frequently Asked Questions
What is CVE-2022-43516?
CVE-2022-43516 is a vulnerability that allows all incoming TCP connections to all programs from any source and to all ports in Windows Firewall after Zabbix agent installation.
How does CVE-2022-43516 affect Microsoft Windows Firewall?
CVE-2022-43516 affects Microsoft Windows Firewall by creating a Firewall Rule that allows all incoming TCP connections to all programs from any source and to all ports after Zabbix agent installation.
What is the severity of CVE-2022-43516?
The severity of CVE-2022-43516 is critical, with a severity value of 9.8.
How does CVE-2022-43516 affect Zabbix Zabbix versions 6.0.10 to 6.0.12?
CVE-2022-43516 affects Zabbix Zabbix versions 6.0.10 to 6.0.12 by creating a Firewall Rule that allows all incoming TCP connections to all programs from any source and to all ports in Windows Firewall after Zabbix agent installation.
How does CVE-2022-43516 affect Zabbix Zabbix versions 6.2.0 to 6.2.6?
CVE-2022-43516 affects Zabbix Zabbix versions 6.2.0 to 6.2.6 by creating a Firewall Rule that allows all incoming TCP connections to all programs from any source and to all ports in Windows Firewall after Zabbix agent installation.
How can I fix CVE-2022-43516?
To fix CVE-2022-43516, you should update Zabbix to a version that is not affected by the vulnerability and remove the Firewall Rule manually.