First published: Wed Sep 27 2023(Updated: )
An issue in Proxmox Server Solutions GmbH Proxmox VE v.5.4 thru v.8.0, Proxmox Backup Server v.1.1 thru v.3.0, and Proxmox Mail Gateway v.7.1 thru v.8.0 allows a remote authenticated attacker to escalate privileges via bypassing the two-factor authentication component.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Proxmox Backup | >=1.1<=3.0 | |
Proxmox Mail Gateway | >=7.1<=8.0 | |
Proxmox VE | >=5.4<=8.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2023-43320.
This vulnerability affects Proxmox VE versions 5.4 through 8.0, Proxmox Backup Server versions 1.1 through 3.0, and Proxmox Mail Gateway versions 7.1 through 8.0.
The severity of CVE-2023-43320 is high with a CVSS score of 8.8.
A remote authenticated attacker can exploit this vulnerability by bypassing the two-factor authentication component.
Yes, you can find more details about this vulnerability in the following references: [Reference 1](https://bugzilla.proxmox.com/show_bug.cgi?id=4579), [Reference 2](https://bugzilla.proxmox.com/show_bug.cgi?id=4584), [Reference 3](https://github.com/proxmox/proxmox-rs/commit/50b793db8d3421bbfe2bce060a486263f18a90cb).