Vulnerability Analysis: Proxmox VE – Default Credentials with TFA Bypass (CVE-2023-54391)

Proxmox VE - Default Credentials with TFA Bypass (CVE-2023-54391)

Introduction CVE-2023-54391 represents a critical pre-authentication authentication bypass vulnerability in Proxmox Virtual Environment (PVE). Operating at a CVSS 3.1 score of 9.8 (Critical), this security flaw allows unauthenticated remote attackers to completely bypass standard password authentication mechanisms. By manipulating parameters in the login API endpoint, an attacker can gain full superuser (root@pam) access to the underlying hypervisor management plane without knowing the victim