Proxmox Virtual Environment是Proxmox公司开源的一个计算机虚拟化平台。 Proxmox Virtual Environment (VE) 7.0至8.0版本存在授权问题漏洞,该漏洞源于libpve-access-control组件存在认证绕过问题,允许未经身份验证的攻击者通过提供任意tfa-challenge值完全跳过密码验证,以任意现有启用用户身份进行认证,获得未授权访问包括root@pam账户。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Proxmox Server Solutions GmbH | Proxmox Virtual Environment (VE) | 7.0≤ 7.4 |
affected |
8.0 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Proxmox Server Solutions GmbH | Proxmox Virtual Environment (VE) | 7.0 ~ 7.4 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | Detected Proxmox VE was accessible using default root@pam credentials combined with a TFA challenge bypass. An attacker could authenticate as root by submitting the default password "root@pam" along with a crafted tfa-challenge parameter, thereby bypassing two-factor authentication enforcement and gaining full administrative access to the hypervisor management interface. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2023/CVE-2023-54391.yaml | POC Details |
No public POC found.
Login to generate AI POCNo comments yet