« Volver al listado

CVE-2023-48643

Estado: AplazadaCrítica (9.8)—

Shrubbery tac_plus 2.x, 3.x. and 4.x through F4.0.4.28 allows unauthenticated Remote Command Execution. The product allows users to configure authorization checks as shell commands through the tac_plus.cfg configuration file. These are executed when a client sends an authorization request with a username that has pre-authorization directives configured. However, it is possible to inject additional commands into these checks because strings from TACACS+ packets are used as command-line arguments.

Leer descripción completaMostrar menos

If the installation lacks a a pre-shared secret (there is no pre-shared secret by default), then the injection can be triggered without authentication. (The attacker needs to know a username configured to use a pre-authorization command.) NOTE: this is related to CVE-2023-45239 but the issue is in the original Shrubbery product, not Meta's fork.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-48643",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-48643",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "poc"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-08-20T15:59:52.293639Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    },
    {
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:shrubbery:tac_plus_2x:*:*:*:*:*:*:*:*"
          ],
          "vendor": "shrubbery",
          "product": "tac_plus_2x",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "f_4.0.4.28"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:a:shrubbery:tac_plus_3x:*:*:*:*:*:*:*:*"
          ],
          "vendor": "shrubbery",
          "product": "tac_plus_3x",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "f_4.0.4.28"
            }
          ],
          "defaultStatus": "unknown"
        },
        {
          "cpes": [
            "cpe:2.3:a:shrubbery:tac_plus_4x:*:*:*:*:*:*:*:*"
          ],
          "vendor": "shrubbery",
          "product": "tac_plus_4x",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "versionType": "custom",
              "lessThanOrEqual": "f_4.0.4.28"
            }
          ],
          "defaultStatus": "unknown"
        }
      ]
    }
  ],
  "published": "2024-05-16T16:15:08.437",
  "references": [
    {
      "url": "https://github.com/takeshixx/tac_plus-pre-auth-rce",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://github.com/takeshixx/tac_plus-pre-auth-rce",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-94"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Shrubbery tac_plus 2.x, 3.x. and 4.x through F4.0.4.28 allows unauthenticated Remote Command Execution. The product allows users to configure authorization checks as shell commands through the tac_plus.cfg configuration file. These are executed when a client sends an authorization request with a username that has pre-authorization directives configured. However, it is possible to inject additional commands into these checks because strings from TACACS+ packets are used as command-line arguments. If the installation lacks a a pre-shared secret (there is no pre-shared secret by default), then the injection can be triggered without authentication. (The attacker needs to know a username configured to use a pre-authorization command.) NOTE: this is related to CVE-2023-45239 but the issue is in the original Shrubbery product, not Meta's fork."
    },
    {
      "lang": "es",
      "value": "Shrubbery tac_plus 2.x, 3.x. y 4.x hasta F4.0.4.28 permite la ejecución de comandos remotos no autenticados. El producto permite a los usuarios configurar comprobaciones de autorización como comandos de shell a través del archivo de configuración tac_plus.cfg. Estos se ejecutan cuando un cliente envía una solicitud de autorización con un nombre de usuario que tiene directivas de autorización previa configuradas. Sin embargo, es posible inyectar comandos adicionales en estas comprobaciones porque las cadenas de los paquetes TACACS+ se utilizan como argumentos de la línea de comandos. Si la instalación carece de un secreto previamente compartido (no hay ningún secreto previamente compartido de forma predeterminada), entonces la inyección se puede activar sin autenticación. (El atacante necesita conocer un nombre de usuario configurado para usar un comando de autorización previa). NOTA: esto está relacionado con CVE-2023-45239, pero el problema está en el producto Shrubbery original, no en la bifurcación de Meta."
    }
  ],
  "lastModified": "2026-06-17T06:34:41.163",
  "sourceIdentifier": "cve@mitre.org"
}