SecBoard
Zurück zur CVE-Übersicht

CVE-2023-54391

CRITICAL(9.8)

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Risk Signal Score25/100 — MITTEL
  • CVSS 9.8 — Kritisch

Erwähnungen (letzte 60 Tage)

Artikel

EPSS-Score

1.7%

Exploit-Wahrscheinlichkeit (30 Tage)

CVSS Score

9.8

Technische Schwere

SecBoard-Einordnung

CVE-2023-54391 betrifft Proxmox Virtual Environment (VE) Versionen 7.0 bis 8.0 und ist eine Authentifizierungs-Bypass-Schwachstelle in libpve-access-control vor Version 8.0.4. Sie ermöglicht es nicht authentifizierten Angreifern, sich als jeder existierende, aktivierte Benutzer ohne konfigurierten zweiten Faktor anzumelden. Dies kann durch das Senden eines beliebigen tfa-challenge-Wertes an den API-Login-Endpunkt erreicht werden, wodurch die Passwortüberprüfung vollständig umgangen wird und unbefugter Zugriff, einschließlich auf das root@pam-Konto, erlangt werden kann.

KI-gestützte Einordnung auf Basis der NVD-Daten.

Beschreibung

Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers to authenticate as any existing enabled user without a configured second factor by supplying an arbitrary tfa-challenge value in the API login endpoint. Attackers can send a POST request to the access ticket API endpoint with any value in the tfa-challenge parameter to completely skip password verification, gaining unauthorized access including to the root@pam account. All affected releases are end of life.

Referenzen