{"id":2469,"date":"2022-02-24T14:17:25","date_gmt":"2022-02-24T16:17:25","guid":{"rendered":"https:\/\/teknomers.com\/fr\/index.php\/alertes-cisa-sur-les-failles-activement-exploitees-dans-la-plate-forme-de-surveillance-reseau-zabbix\/"},"modified":"2022-02-24T14:17:41","modified_gmt":"2022-02-24T16:17:41","slug":"alertes-cisa-sur-les-failles-activement-exploitees-dans-la-plate-forme-de-surveillance-reseau-zabbix","status":"publish","type":"post","link":"https:\/\/teknomers.com\/fr\/alertes-cisa-sur-les-failles-activement-exploitees-dans-la-plate-forme-de-surveillance-reseau-zabbix\/","title":{"rendered":"Alertes CISA sur les failles activement exploit\u00e9es dans la plate-forme de surveillance r\u00e9seau Zabbix"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div id=\"articlebody\">\n<div class=\"separator\" style=\"clear: both\"><\/div>\n<p>La Cybersecurity and Infrastructure Security Agency (CISA) des \u00c9tats-Unis a <a rel=\"nofollow noopener\" href=\"https:\/\/www.cisa.gov\/uscert\/ncas\/current-activity\/2022\/02\/22\/cisa-adds-two-known-exploited-vulnerabilities-catalog\" target=\"_blank\">averti<\/a> d&#8217;exploitation active de deux failles de s\u00e9curit\u00e9 affectant la plate-forme de surveillance d&#8217;entreprise open source Zabbix, les ajoutant \u00e0 son <a rel=\"nofollow noopener\" href=\"https:\/\/www.osintessentials.com\/about\" target=\"_blank\">Catalogue des vuln\u00e9rabilit\u00e9s exploit\u00e9es connues<\/a>.<\/p>\n<p>En plus de cela, la CISA recommande \u00e9galement que les agences du Federal Civilian Executive Branch (FCEB) corrigent tous les syst\u00e8mes contre les vuln\u00e9rabilit\u00e9s d&#8217;ici le 8 mars 2022 afin de r\u00e9duire leur exposition aux cyberattaques potentielles.<\/p>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/dset2\" target=\"_blank\" title=\"Automatic GitHub Backups\"><img loading=\"lazy\" decoding=\"async\" alt=\"Sauvegardes GitHub automatiques\" class=\"lazyload\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/02\/Alertes-CISA-sur-les-failles-activement-exploitees-dans-la-plate-forme.png\" width=\"300\" height=\"250\" \/><\/a><\/div>\n<p>Suivi comme <a rel=\"nofollow noopener\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-23131\" target=\"_blank\">CVE-2022-23131<\/a> (score CVSS : 9,8) et <a rel=\"nofollow noopener\" href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2022-23134\" target=\"_blank\">CVE-2022-23134<\/a> (score CVSS\u00a0: 5,3), les lacunes pourraient entra\u00eener la compromission de r\u00e9seaux complets, permettant \u00e0 un acteur malveillant non authentifi\u00e9 d&#8217;\u00e9lever les privil\u00e8ges et d&#8217;obtenir un acc\u00e8s administrateur \u00e0 l&#8217;interface Zabbix ainsi que d&#8217;apporter des modifications de configuration.<\/p>\n<p><iframe loading=\"lazy\" title=\"Zabbix Unsafe Session Storage - CVE-2022-23131\" width=\"640\" height=\"360\" src=\"https:\/\/www.youtube.com\/embed\/5dci1i6Fq3M?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe><\/p>\n<p>Thomas Chauchefoin de SonarSource a \u00e9t\u00e9 cr\u00e9dit\u00e9 d&#8217;avoir d\u00e9couvert et signal\u00e9 les deux failles, qui affectent les versions de Zabbix Web Frontend jusqu&#8217;\u00e0 et y compris 5.4.8, 5.0.18 et 4.0.36.  Les probl\u00e8mes ont depuis \u00e9t\u00e9 r\u00e9solus dans les versions 5.4.9, 5.0.9 et 4.0.37 livr\u00e9es fin d\u00e9cembre 2021.<\/p>\n<div class=\"ad_two clear\"><a rel=\"nofollow noopener\" href=\"https:\/\/go.thn.li\/cs-jan-webinar-inside\" target=\"_blank\" title=\"Prevent Data Breaches\"><img loading=\"lazy\" decoding=\"async\" alt=\"Emp\u00eacher les violations de donn\u00e9es\" class=\"lazyload\" src=\"https:\/\/teknomers.com\/fr\/wp-content\/uploads\/2022\/02\/1645701002_140_Dridex-Malware-Deploiement-Entropy-Ransomware-sur-des-ordinateurs-pirates.png\" width=\"728\" height=\"90\" \/><\/a><\/div>\n<p>Les deux failles sont le r\u00e9sultat de ce que la soci\u00e9t\u00e9 appelle un &#8220;stockage de session non s\u00e9curis\u00e9&#8221;, permettant aux attaquants de contourner l&#8217;authentification et d&#8217;ex\u00e9cuter du code arbitraire.  Il convient toutefois de souligner que les failles n&#8217;affectent que les instances o\u00f9 l&#8217;authentification unique SAML (Security Assertion Markup Language) est activ\u00e9e.<\/p>\n<div class=\"video-container\">\n<p><iframe loading=\"lazy\" title=\"Zabbix Unsafe Session Storage - CVE-2022-23134\" width=\"640\" height=\"360\" src=\"https:\/\/www.youtube.com\/embed\/-2wDXMck6A8?feature=oembed\" frameborder=\"0\" allow=\"accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share\" referrerpolicy=\"strict-origin-when-cross-origin\" allowfullscreen><\/iframe><\/p>\n<\/div>\n<p>&#8220;Fournissez toujours un acc\u00e8s aux services sensibles avec des acc\u00e8s internes \u00e9tendus (par exemple, l&#8217;orchestration, la surveillance) via des VPN ou un ensemble restreint d&#8217;adresses IP, renforcez les autorisations du syst\u00e8me de fichiers pour emp\u00eacher les modifications involontaires, supprimez les scripts de configuration, etc.&#8221; Chauchefoin <a rel=\"nofollow noopener\" href=\"https:\/\/blog.sonarsource.com\/zabbix-case-study-of-unsafe-session-storage\" target=\"_blank\">mentionn\u00e9<\/a>.<\/p>\n<p><\/p>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/thehackernews.com\/2022\/02\/cisa-alerts-on-actively-exploited-flaws.html\" rel=\"nofollow noopener\" target=\"_blank\">ttn-fr-57<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>La Cybersecurity and Infrastructure Security Agency (CISA) des \u00c9tats-Unis a averti d&#8217;exploitation active de deux failles de s\u00e9curit\u00e9 affectant la plate-forme de surveillance d&#8217;entreprise open source Zabbix, les ajoutant \u00e0 son Catalogue des vuln\u00e9rabilit\u00e9s exploit\u00e9es connues. En plus de cela, la CISA recommande \u00e9galement que les agences du Federal Civilian Executive Branch (FCEB) corrigent tous [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":2470,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[4807,4804,4805,4168,4158,4165,4161,429,4808,4806,4157,4159,4171,4170,65,4167,4160,4163,4162,4809,4810,4172,4169,60,3492,4166,4164,4811],"class_list":["post-2469","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technologie","tag-activement","tag-alertes","tag-cisa","tag-comment-pirater","tag-cyber-actualites","tag-cyber-attaques","tag-cyber-mises-a-jour","tag-dans","tag-exploitees","tag-failles","tag-lactualite-de-la-cybersecurite","tag-lactualite-de-la-cybersecurite-aujourdhui","tag-lactualite-des-hackers","tag-la-securite-des-informations","tag-les","tag-logiciel-malveillant-de-ransomware","tag-mises-a-jour-de-la-cybersecurite","tag-nouvelles-de-piratage","tag-nouvelles-de-pirates","tag-plateforme","tag-reseau","tag-securite-informatique","tag-securite-internet","tag-sur","tag-surveillance","tag-violation-de-donnees","tag-vulnerabilite-logicielle","tag-zabbix"],"_links":{"self":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/2469","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/comments?post=2469"}],"version-history":[{"count":0,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/posts\/2469\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media\/2470"}],"wp:attachment":[{"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/media?parent=2469"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/categories?post=2469"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/teknomers.com\/fr\/wp-json\/wp\/v2\/tags?post=2469"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}