CVE-2023-54391

Summary

Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers to authenticate as any existing enabled user without a configured second factor by supplying an arbitrary tfa-challenge value in the API login endpoint. Attackers can send a POST request to the access ticket API endpoint with any value in the tfa-challenge parameter to completely skip password verification, gaining unauthorized access including to the root@pam account. All affected releases are end of life.

Affected Software

VendorProductVersion RangeStatus
Proxmox Server Solutions GmbHProxmox Virtual Environment (VE)7.0 <= 7.4affected
Proxmox Server Solutions GmbHProxmox Virtual Environment (VE)8.0affected

Weaknesses

  • CWE-304: Missing Critical Step in Authentication

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: total

References