CyberRota Analysis
AI-GeneratedProxmox Virtual Environment versions 7.0 through 8.0 are vulnerable to an authentication bypass flaw that allows unauthenticated attackers to gain access as any enabled user, including root, by manipulating the tfa-challenge parameter in the API login endpoint. This critical vulnerability poses a severe risk of unauthorized access to sensitive systems and data. Organizations using affected versions should prioritize immediate remediation, as all impacted releases are no longer supported.
Original NVD Description
Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers to authenticate as any existing enabled user without a configured second factor by supplying an arbitrary tfa-challenge value in the API login endpoint. Attackers can send a POST request to the access ticket API endpoint with any value in the tfa-challenge parameter to completely skip password verification, gaining unauthorized access including to the root@pam account. All affected releases are end of life.