Record summary

CVE-2023-37265 has a selected CVSS score of 9.8 (critical); EIP currently links 1 Nuclei template.

Description

CasaOS is an open-source Personal Cloud system. Due to a lack of IP address verification an unauthenticated attackers can execute arbitrary commands as `root` on CasaOS instances. The problem was addressed by improving the detection of client IP addresses in `391dd7f`. This patch is part of CasaOS 0.4.4. Users should upgrade to CasaOS 0.4.4. If they can't, they should temporarily restrict access to CasaOS to untrusted users, for instance by not exposing it publicly.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

CISA SSVC decision

ExploitationNone
AutomatableYes
Technical impactTotal

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 10, 2024 · Source: CVE List

Affected products and versions

3
ProductSourceVersion rangeStatus
CVE List< 0.4.4affected

Default status: unknown

CVE ListBefore 0.4.4affected

github.com/IceWhaleTech/CasaOS-Gateway

Browse Go / github.com/IceWhaleTech/CasaOS-Gateway
GitHub AdvisoryBefore 0.4.4 · Fixed in 0.4.4affected

Nuclei templates

1
ProjectDiscoveryCRITICALCasaOS < 0.4.4 - Authentication Bypass via Internal IPCVSS 9.8

CasaOS is an open-source Personal Cloud system. Due to a lack of IP address verification an unauthenticated attackers can execute arbitrary commands as `root` on CasaOS instances. The problem was addressed by improving the detection of client IP addresses in `391dd7f`. This patch is part of CasaOS 0.4.4. Users should upgrade to CasaOS 0.4.4. If they can't, they should temporarily restrict access to CasaOS to untrusted users, for instance by not exposing it publicly.

Impact

Successful exploitation allows unauthorized access to the CasaOS system.

Remediation

The problem was addressed by improving the detection of client IP addresses in 391dd7f. This patch is part of CasaOS 0.4.4.

WeaknessesCWE-306
Authorsiamnoooob, DhiyaneshDK, pdresearch
Template tagscvecve2023osscasaosjwticewhalevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CPE: cpe:2.3:o:icewhale:casaos:*:*:*:*:*:*:*:*
Shodan: http.html:"/CasaOS-UI/public/index.html"
Shodan: http.html:"/casaos-ui/public/index.html"
FOFA: body="/CasaOS-UI/public/index.html"
FOFA: body="/casaos-ui/public/index.html"

Source: ProjectDiscovery

References

6