Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2023-54391— Proxmox VE 7.0-8.0 Authentication Bypass via tfa-challenge Parameter

Quick assessment

Affected
Proxmox Server Solutions GmbH Proxmox Virtual Environment (VE)
Exploitation
Public or AI PoC available; prioritize validation
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

Proxmox Virtual Environment是Proxmox公司开源的一个计算机虚拟化平台。 Proxmox Virtual Environment (VE) 7.0至8.0版本存在授权问题漏洞,该漏洞源于libpve-access-control组件存在认证绕过问题,允许未经身份验证的攻击者通过提供任意tfa-challenge值完全跳过密码验证,以任意现有启用用户身份进行认证,获得未授权访问包括root@pam账户。

CVSS 9.8 · Critical EPSS 1.75% · P77

Public Exploits 1

Affected Version Matrix 2

VendorProduct Version RangeStatus
Proxmox Server Solutions GmbH Proxmox Virtual Environment (VE) 7.0≤ 7.4 affected
8.0 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2023-54391

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Proxmox VE 7.0-8.0 Authentication Bypass via tfa-challenge Parameter
Source: CVE Program / CVE List V5
Vulnerability Description
Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers to authenticate as any existing enabled user without a configured second factor by supplying an arbitrary tfa-challenge value in the API login endpoint. Attackers can send a POST request to the access ticket API endpoint with any value in the tfa-challenge parameter to completely skip password verification, gaining unauthorized access including to the root@pam account. All affected releases are end of life.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
认证中关键步骤缺失
Source: CVE Program / CVE List V5
Vulnerability Title
Proxmox Virtual Environment 授权问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Proxmox Virtual Environment是Proxmox公司开源的一个计算机虚拟化平台。 Proxmox Virtual Environment (VE) 7.0至8.0版本存在授权问题漏洞,该漏洞源于libpve-access-control组件存在认证绕过问题,允许未经身份验证的攻击者通过提供任意tfa-challenge值完全跳过密码验证,以任意现有启用用户身份进行认证,获得未授权访问包括root@pam账户。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
Proxmox Server Solutions GmbH Proxmox Virtual Environment (VE) 7.0 ~ 7.4 -

II. Public POCs for CVE-2023-54391

# POC Description Source Link Shenlong Link
1 Detected Proxmox VE was accessible using default root@pam credentials combined with a TFA challenge bypass. An attacker could authenticate as root by submitting the default password "root@pam" along with a crafted tfa-challenge parameter, thereby bypassing two-factor authentication enforcement and gaining full administrative access to the hypervisor management interface. https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-54391.yaml POC Details
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2023-54391

登录查看更多情报信息。

Patches & Fixes for CVE-2023-54391 (2)

Vendor Advisories for CVE-2023-54391 (1)

Vendor Pages for CVE-2023-54391 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2023-54391

No comments yet


Leave a comment