CVE-2023-48251

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Jan 10, 2024
Updated: Jan 17, 2024
CWE ID 798

Summary

CVE-2023-48251 is a newly disclosed vulnerability that poses a significant threat to SSH-protected systems. Malicious actors can exploit this issue to authenticate as the root user remotely, without needing valid credentials. This hidden hard-coded account goes undetected by default configurations, making it an attractive target for attackers. Once authenticated, they can gain full control over the compromised system, potentially leading to data theft, unauthorized modifications, or other malicious activities. System administrators are strongly advised to update their SSH servers to patch this vulnerability and secure their environments against potential attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share