CVE-2023-43320
Proxmox VE 7.4-1 TOTP Brute Force
Severity Score
8.8
*CVSS v3.1
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
Track*
*SSVC
Descriptions
An issue in Proxmox Server Solutions GmbH Proxmox VE v.5.4 thru v.8.0, Proxmox Backup Server v.1.1 thru v.3.0, and Proxmox Mail Gateway v.7.1 thru v.8.0 allows a remote authenticated attacker to escalate privileges via bypassing the two-factor authentication component.
Un problema en Proxmox Server Solutions GmbH Proxmox VE v.5.4 hasta v.8.0, Proxmox Backup Server v.1.1 hasta v.3.0 y Proxmox Mail Gateway v.7.1 hasta v.8.0 permite a un atacante autenticado remoto escalar privilegios evitando el Componente de autenticación de dos factores.
Proxmox VE versions 5.4 through 7.4-1 suffer from a TOTP brute forcing vulnerability.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Track*
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2023-09-18 CVE Reserved
- 2023-09-27 CVE Published
- 2024-10-03 EPSS Updated
- 2024-11-26 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (4)
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://github.com/proxmox/proxmox-rs/commit/50b793db8d3421bbfe2bce060a486263f18a90cb | 2024-02-02 |
URL | Date | SRC |
---|---|---|
https://bugzilla.proxmox.com/show_bug.cgi?id=4579 | 2024-02-02 | |
https://bugzilla.proxmox.com/show_bug.cgi?id=4584 | 2024-02-02 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Proxmox Search vendor "Proxmox" | Backup Server Search vendor "Proxmox" for product "Backup Server" | >= 1.1 <= 3.0 Search vendor "Proxmox" for product "Backup Server" and version " >= 1.1 <= 3.0" | - |
Affected
| ||||||
Proxmox Search vendor "Proxmox" | Proxmox Mail Gateway Search vendor "Proxmox" for product "Proxmox Mail Gateway" | >= 7.1 <= 8.0 Search vendor "Proxmox" for product "Proxmox Mail Gateway" and version " >= 7.1 <= 8.0" | - |
Affected
| ||||||
Proxmox Search vendor "Proxmox" | Virtual Environment Search vendor "Proxmox" for product "Virtual Environment" | >= 5.4 <= 8.0 Search vendor "Proxmox" for product "Virtual Environment" and version " >= 5.4 <= 8.0" | - |
Affected
|