CVE-2023-54329: Inbit Messenger 4.9.0 - Unauthenticated Remote Command Execution (RCE)
Inbit Messenger 4.6.0 - 4.9.0 contains a remote command execution vulnerability that allows unauthenticated attackers to execute arbitrary commands by exploiting a stack overflow in the messenger's protocol. Attackers can send specially crafted XML packets to port 10883 with a malicious payload to trigger the vulnerability and execute commands with system privileges.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-54329?
CVE-2023-54329 is classified as a critical vulnerability due to its potential for unauthenticated remote command execution, allowing attackers to execute arbitrary commands.
How do I fix CVE-2023-54329?
To mitigate CVE-2023-54329, upgrade Inbit Messenger to version 4.9.1 or later, which contains necessary security patches.
What versions of Inbit Messenger are affected by CVE-2023-54329?
Inbit Messenger versions 4.6.0 to 4.9.0 are vulnerable to CVE-2023-54329.
Can CVE-2023-54329 be exploited remotely?
Yes, CVE-2023-54329 allows unauthenticated remote attackers to exploit the vulnerability to execute commands.
What type of vulnerability is CVE-2023-54329?
CVE-2023-54329 is a remote command execution vulnerability caused by a stack overflow in the messenger's protocol.