← Terug naar overzicht

CVE-2023-54391 is a critical authentication bypass vulnerability affecting Proxmox Virtual Environment (VE) versions 7.0 through 8.0, specifically in libpve-access-control before version 8.0.4. Unauthenticated attackers can exploit this flaw by sending a POST request to the access ticket API endpoint with an arbitrary value in the tfa-challenge parameter, completely bypassing password verification. This allows attackers to authenticate as any existing enabled user that does not have a second factor configured, including the highly privileged root@pam account. The vulnerability requires no credentials and provides full unauthorized access to the hypervisor management interface. A fix was introduced in libpve-access-control 8.0.4. All affected releases (7.0–8.0) are end of life and no longer receive official support patches. Organizations still running these versions are at significant risk and should upgrade immediately or implement network-level controls.

Affected products

  • Proxmox Virtual Environment 7.0
  • Proxmox Virtual Environment 8.0
  • libpve-access-control

Related CVE's

  • CVE-2023-54391

Categories

  • Cloud & Virtualization
  • Identity & Access
  • Zero-Day Vulnerabilities