CVE-2023-27533 is a high-severity input validation vulnerability in curl versions prior to 8.0, specifically affecting its TELNET protocol communication, and impacting products like fedoraproject, haxx, netapp, and splunk. An attacker can exploit this by injecting malicious username and TELNET options during server negotiation, potentially leading to arbitrary code execution if an application accepts user input. With a CVSS score of 8.8, this vulnerability presents a high risk due to its network attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion, indicating a low current exploitation status.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.0.0, <= 7.881CPE matchmatch criteria | cpe:2.3:a:haxx:curl:*:*:*:*:*:*:*:* | ||
36CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:active_iq_unified_manager:-:*:*:*:*:vmware_vsphere:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:a:netapp:clustered_data_ontap:9.0:-:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
CVE-2023-27533
Sep 10, 2024August Third Party Package Updates in Splunk Universal Forwarder
Aug 30, 2023curl: TELNET option IAC injection
Mar 20, 2023TELNET option IAC injection
Mar 20, 2023A vulnerability in input validation exists in curl <8.0 during communication using the TELNET protocol may allow an attacker to pass on maliciously crafted user name and "telnet options" during server negotiation. The lack of proper input scrubbing allows an attacker to send content or perform option negotiation without the application's intent. This vulnerability could be exploited if an application allows user input thereby enabling attackers to execute arbitrary code on the system.
Mar 14, 2023