PT-2023-29466 · Tac Plus · Tac Plus

Takeshixx

·

Publicado

2023-10-06

·

Atualizado

2024-09-19

·

CVE-2023-45239

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions tac plus versions prior to commit 4fdf178
Description A lack of input validation exists in tac plus, which, when pre or post auth commands are enabled, allows an attacker who can control the username, rem-addr, or NAC address sent to tac plus to inject shell commands and gain remote code execution on the tac plus server.
Recommendations For versions prior to commit 4fdf178, consider disabling pre or post auth commands until a patch is available. Restrict access to the tac plus server to minimize the risk of exploitation. Avoid using the username, rem-addr, or NAC address parameters in the affected tac plus configuration until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2023-45239
GHSA-P334-5R3G-4VX3

Produtos afetados

Tac Plus