CVE-2023-22497 is a critical authentication bypass vulnerability affecting Netdata agents, specifically impacting the streaming feature. An attacker can leverage a valid Netdata agent's MACHINE_GUID as an API key, gaining unauthorized access to parent agents configured to aggregate data from child agents. With a CVSS score of 9.1, this vulnerability is easily exploitable over the network with low attack complexity, potentially leading to high confidentiality and integrity impacts. There is currently no public exploit code available, and the vulnerability has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.37.0CPE matchmatch criteria | cpe:2.3:a:netdata:netdata:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.