CVE-2023-54391: Proxmox VE - Default Credentials with TFA Bypass
HoneyLabs honeypots recorded 7 probes matching CVE-2023-54391 from 4 distinct source IP addresses in the last 7 days. Severity is rated critical.
Request paths that identify it
- /api2/json/access/ticket
Addresses probing it
| Source IP | Probes | Network | Country |
|---|---|---|---|
| 104.28.192.66 | 4 | Cloudflare, Inc. | United Kingdom |
| 45.175.252.36 | 1 | Alma Jessica Gallegos Gutierrez | Mexico |
| 45.151.101.38 | 1 | Aeza Group LLC | Russia |
| 154.38.179.91 | 1 | Contabo Inc. | United States |
Networks it comes from
| ASN | Organisation | Probes | Source IPs |
|---|---|---|---|
| AS13335 | Cloudflare, Inc. | 4 | 1 |
| AS216246 | Aeza Group LLC | 1 | 1 |
| AS40021 | Contabo Inc. | 1 | 1 |
| AS265585 | Alma Jessica Gallegos Gutierrez | 1 | 1 |
Captured requests
- /api2/json/access/ticket
HTTP client fingerprints (JA4H)
- po11nn0700_eeaba25bea7f
- po11nn0600_def5433ae821
- po11nn0600_36b368ee4bc7
- po11nn0500_b4ba55311b46
CVE report
CVE report
Open a specific CVE from the CVE tracker.