New on LowEndTalk? Please Register and read our Community Rules.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
PSA: Update your Proxmox VE installations (Authentication bypass in EOL Proxmox VE releases)
https://forum.proxmox.com/posts/867929/
TL;DR:
- Older, EOL versions of Proxmox VE have an actively exploited vulnerability with the
libpve-access-controlpackage (Affected: >= 7.0-7 and < 8.0.4) - If 8006 WebUI/API is exposed to public Internet, attackers can bypass passwords entirely to authenticate as root, due to a cursed 2FA implementation
- Current supported PVE versions (9.x) are completely safe
- If you are still running PVE 7.x-8.0.3, restrict access to port 8006 and upgrade immediately

Comments
I was one of the original reporters in the advisory.
Sharing my repo with the fixes, root cause analysis, and detection rules: https://github.com/neeythann/Proxmox-VE-7-RCE
@trumvps is this what you mentioned?
oh, it doesn't affect much anyway
edit: okay chatgpt scheduled task just sent me an update, which the api /access/ticket can be bypassed completely
Will these make it secure if im unable to patch mine?
I just don't open Proxmox to the internet.
Well, glad nobody is using EOL software
I didn't upgrade my private proxmox nodes yet....
Luckly, Proxmox is firewalled anyway.
Its time to upgrade today I guess.
I just put my Web UI behind cloudflared tunnel and have a one time pin to it...
Please dont scan my IPs I think one of mine is running EOL version
Nevermind, the server just hang up while upgrading it.
Fuck me, but its Safe now, until someone at OVH reboots the server.
The issue is why do you expose Promox dashboard to public internet
The amount of services exposed that should not be down to human error, AI usage, or simple arrogance amazes me.
At anytime there are literally millions of exploitable devices active on the internet right now.
you have too many, I’ll pass
For sure, yes.
There are still some incompetent VPS providers/summer hosts exist, running ancient versions of PVE and the ModulesGarden PVE WHMCS Module, that the end user VNC console connects directly to Internet exposed PVE dashboards rather than going through a secure proxy. They won't do security audits/upgrades until things really breaks.