Vulnerability Analysis: Proxmox VE – Default Credentials with TFA Bypass (CVE-2023-54391)

Proxmox VE - Default Credentials with TFA Bypass (CVE-2023-54391)

Introduction CVE-2023-54391 represents a critical pre-authentication authentication bypass vulnerability in Proxmox Virtual Environment (PVE). Operating at a CVSS 3.1 score of 9.8 (Critical), this security flaw allows unauthenticated remote attackers to completely bypass standard password authentication mechanisms. By manipulating parameters in the login API endpoint, an attacker can gain full superuser (root@pam) access to the underlying hypervisor management plane without knowing the victim

Critical CUPS Vulnerability (CVE 9.9) in Linux

Critical CUPS Vulnerability (CVE 9.9) on Linux: Immediate Security Measures Required

Introduction A major vulnerability affecting Linux systems has been discovered in the Common Unix Printing System (CUPS). This vulnerability, classified with a CVSS score of 9.9, poses a severe risk to systems that rely on CUPS for managing printing tasks. It allows attackers to exploit the system remotely, enabling privilege escalation and potential full system takeover. This article explores the CUPS printing