Vulnerability CVE-2023-43320


Published: 2023-09-27   Modified: 2023-09-28

Description:
An issue in Proxmox Server Solutions GmbH Proxmox VE v.5.4 thru v.8.0, Proxmox Backup Server v.1.1 thru v.3.0, and Proxmox Mail Gateway v.7.1 thru v.8.0 allows a remote authenticated attacker to escalate privileges via bypassing the two-factor authentication component.

See advisories in our WLB2 database:
Topic
Author
Date
Low
Proxmox VE 7.4-1 TOTP Brute Force
Gabe Rust
02.02.2024

 References:
https://github.com/proxmox/proxmox-rs/commit/50b793db8d3421bbfe2bce060a486263f18a90cb
https://bugzilla.proxmox.com/show_bug.cgi?id=4579
https://bugzilla.proxmox.com/show_bug.cgi?id=4584

Copyright 2024, cxsecurity.com

 

Back to Top