CVE-2023-37265 is a critical authentication bypass vulnerability affecting CasaOS versions prior to 0.4.4, specifically impacting icewhale casaos and casaos-gateway. This flaw allows unauthenticated attackers to execute arbitrary commands as root due to insufficient IP address verification. With a CVSS score of 9.8 (Critical) and an EPSS score of 0.91121, it presents a high risk of complete compromise (Confidentiality, Integrity, Availability). While not listed in CISA KEV, Nuclei templates exist for exploitation, and it has garnered significant community discussion, indicating potential for active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.4.4CPE matchmatch criteria | cpe:2.3:o:icewhale:casaos:*:*:*:*:*:*:*:* | ||
0.4.4CPE matchmatch criteria | cpe:2.3:o:icewhale:casaos:0.4.4:alpha1:*:*:*:*:*:* | ||
0.4.4CPE matchmatch criteria | cpe:2.3:o:icewhale:casaos:0.4.4:alpha2:*:*:*:*:*:* | ||
0.4.4CPE matchmatch criteria | cpe:2.3:o:icewhale:casaos:0.4.4:alpha3:*:*:*:*:*:* | ||
0.4.4CPE matchmatch criteria | cpe:2.3:o:icewhale:casaos:0.4.4:alpha4:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.