vendor:
Proxmox VE
by:
Cory Cline, Gabe Rust
7.1
CVSS
HIGH
Brute Force Attack
307
CWE
Product Name: Proxmox VE
Affected Version From: 45387
Affected Version To: 7.4-1
Patch Exists: NO
Related CWE: CVE-2023-43320
CPE: -
Platforms Tested: Debian
2023
Proxmox VE TOTP Brute Force
The Proxmox VE TOTP Brute Force exploit allows an attacker to perform a brute force attack on the Time-based One-Time Password (TOTP) mechanism used in Proxmox VE. By continuously guessing TOTP codes, an attacker can potentially gain unauthorized access to the system. This vulnerability has been assigned the CVE ID CVE-2023-43320.
Mitigation:
To mitigate this vulnerability, it is recommended to implement account lockout mechanisms after a certain number of failed login attempts. Additionally, enabling multi-factor authentication (MFA) can add an extra layer of security.