Impact
An unauthenticated attacker can supply any value for the tfa‑challenge parameter to the Proxmox VE login API, causing the system to skip password verification. This vulnerability, mapped to CWE‑304, enables the attacker to authenticate as any active user, including the root@pam account, thereby granting full control of the host.
Affected Systems
All Proxmox Virtual Environment releases from version 7.0 through 8.0, prior to the 8.0.4 update. Every affected build has reached end‑of‑life and receives no further security updates.
Risk and Exploitability
The CVSS score of 9.3 reflects a critical severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, but the lack of authentication and the ability to remotely send the HTTP POST request make the vulnerability highly exploitable from any network location that can reach the API endpoint.
OpenCVE Enrichment