← volver
CVE-2023-54391criticalexplotación observadaCWE-304

Proxmox VE 7.0-8.0 Authentication Bypass via tfa-challenge Parameter

47Vexday Risk Score

Prioriza la corrección. Ella explotación observada por VulnCheck.

ssvc Actcvss 9.3
de la publicación al arma
Publicada en NVD1 sept
VulnCheck1 sept
probabilidad de explotación
explotación observada
VulnCheck
Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers to authenticate as any existing enabled user without a configured second factor by supplying an arbitrary tfa-challenge value in the API login endpoint. Attackers can send a POST request to the access ticket API endpoint with any value in the tfa-challenge parameter to completely skip password verification, gaining unauthorized access including to the root@pam account. All affected releases are end of life.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N