{"id":"CVE-2023-43320","details":"An issue in Proxmox Server Solutions GmbH Proxmox VE v.5.4 thru v.8.0, Proxmox Backup Server v.1.1 thru v.3.0, and Proxmox Mail Gateway v.7.1 thru v.8.0 allows a remote authenticated attacker to escalate privileges via bypassing the two-factor authentication component.","modified":"2026-08-12T03:51:14.452832219Z","published":"2023-09-27T00:00:00Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/43xxx/CVE-2023-43320.json","cna_assigner":"mitre"},"references":[{"type":"WEB","url":"http://packetstormsecurity.com/files/176967/Proxmox-VE-7.4-1-TOTP-Brute-Force.html"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2023/43xxx/CVE-2023-43320.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2023-43320"},{"type":"REPORT","url":"https://bugzilla.proxmox.com/show_bug.cgi?id=4579"},{"type":"REPORT","url":"https://bugzilla.proxmox.com/show_bug.cgi?id=4584"},{"type":"FIX","url":"https://github.com/proxmox/proxmox-rs/commit/50b793db8d3421bbfe2bce060a486263f18a90cb"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/proxmox/proxmox-rs","events":[{"introduced":"0"},{"fixed":"50b793db8d3421bbfe2bce060a486263f18a90cb"}],"database_specific":{"source":"REFERENCES"}}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2023-43320.json"}}],"schema_version":"1.9.0"}