Zabbix API and Frontend login lockout mechanism has a flaw where several unsuccessful login requests are not properly counted towards the block counter if sent simultaneously, potentially allowing for more password guesses than intended.
An attacker with access to Zabbix Frontend or Zabbix API can perform more password guesses than intended.
Update the affected components to their respective fixed versions.