preloader

· · digital-security devops self-hosted virtualization proxmox cve patch-management europe vulnerability-management

A Three-Year-Old Proxmox Bug Just Started Being Exploited, and the Fix Doesn’t Exist for Your Version

Source: SecurityOnline

Proxmox Virtual Environment runs an enormous share of Europe’s self-hosted infrastructure, small hosting providers, MSPs, homelabs, and mid-market companies who wanted a VMware alternative that didn’t come with VMware’s licensing bill. That popularity is exactly why an advisory Proxmox published on September 1 deserves more attention than a routine security bulletin.

A login parameter that skips the password check entirely

CVE-2023-54391 lives in libpve-access-control, the package behind Proxmox VE’s login API. The endpoint accepts a tfa-challenge parameter for accounts that use two-factor authentication. For accounts that don’t have 2FA configured, the presence of that parameter, with any value at all, causes the password check to be skipped entirely. Send the parameter, and you’re logged in as any activated user with no second factor, which by default includes root@pam. No credentials, no user interaction, reachable directly over the network against the management API on port 8006. It scores 9.8 on CVSS v3.1, and root on the Proxmox host means control of every virtual machine it runs.

Why there’s no patch for the affected versions

The bug was fixed in libpve-access-control 8.0.4, released in July 2023. That fix never applied to the 7.x branch, and Proxmox VE 7.x has been end of life since July 2024, along with the earliest 8.0 builds. There will be no backport. If you’re still running 7.x, and plenty of hosts are, because a major version upgrade on a production hypervisor isn’t something teams schedule lightly, the only route off this vulnerability is a full upgrade to a supported release, not a patch.

Proxmox says it learned of active exploitation through multiple independent reports arriving within days of each other, and proof-of-concept code is now public, which typically means the pool of attackers trying it widens fast.

What to check today

Run pveversion and confirm you’re on a currently supported Proxmox VE release. If you’re on 7.x, treat this as urgent: an unauthenticated root compromise of your hypervisor is not a “patch in the next maintenance window” problem, it’s a “who else might already be in” problem. Check your access logs for tfa-challenge parameters on login attempts you didn’t originate, and if you find any, assume compromise and start incident response rather than just applying an upgrade.

If you’re running end-of-life infrastructure anywhere in your stack, whether that’s Proxmox, an old hypervisor, or anything else past its support window, and you’re not sure what your real exposure looks like, contact Excello Digital. We help European teams plan and execute upgrades before an old CVE turns into an incident report.

These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional — let us know and we'll correct or remove it.

We’ll help you resolve your infrastructure challenges

Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.

Get in touch!