CVE-2023-54391: Proxmox VE - Default Credentials with TFA Bypass

HoneyLabs honeypots recorded 7 probes matching CVE-2023-54391 from 4 distinct source IP addresses in the last 7 days. Severity is rated critical.

Request paths that identify it

  • /api2/json/access/ticket

Addresses probing it

Source IPProbesNetworkCountry
104.28.192.664Cloudflare, Inc.United Kingdom
45.175.252.361Alma Jessica Gallegos GutierrezMexico
45.151.101.381Aeza Group LLCRussia
154.38.179.911Contabo Inc.United States

Networks it comes from

ASNOrganisationProbesSource IPs
AS13335Cloudflare, Inc.41
AS216246Aeza Group LLC11
AS40021Contabo Inc.11
AS265585Alma Jessica Gallegos Gutierrez11

Captured requests

  • /api2/json/access/ticket

HTTP client fingerprints (JA4H)

  • po11nn0700_eeaba25bea7f
  • po11nn0600_def5433ae821
  • po11nn0600_36b368ee4bc7
  • po11nn0500_b4ba55311b46

CVE report

CVE report

Open a specific CVE from the CVE tracker.