CVE-2023-43631

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Sep 21, 2023
Updated: Sep 28, 2023
CWE ID 522
CWE ID 922

Summary

CVE-2023-43631 is a vulnerability affecting the Pillar eve container in certain versions. The container checks for the existence and content of the "/config/authorized_keys" file during boot. If the file contains a supported public key, the container enables SSH with those keys for root login and opens port 22. An attacker can exploit this by adding their own keys to the file, gaining full control over the system without triggering the "measured boot" mechanism or marking the device as "UUD". The vulnerability exists because the "/config" partition, which is not protected by "measured boot" and is not encrypted, is mutable. The issue was partially addressed in recent commits, which added the config partition measurement to PCR13. However, the vulnerability was made possible in version 9.0.0 when the calculation was moved to PCR14 but not included in the measured boot.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Prioritize, Pinpoint, and Act to Prevent Vulnerability Exploits with Recorded Future

Note: This is just a basic overview providing quick insights into CVE-2023-43631 information. Gain full access to comprehensive CVE data, third party vulnerabilities, compromised credentials and more with Recorded Future
  • Gain complete coverage of your cyber, third party, and physical attack surface
  • Proactively mitigate threats before they turn into costly attacks
  • Make fast, effective, data-driven decisions