CVE-2023-37582 is a critical remote command execution (RCE) vulnerability affecting Apache RocketMQ NameServer versions 5.1.1 and earlier (for 5.x) and 4.9.6 and earlier (for 4.x). This flaw, an incomplete fix for CVE-2023-33246, allows unauthenticated attackers to execute arbitrary commands on the underlying system if the NameServer address is exposed externally without proper access controls. With a CVSS score of 9.8 (CRITICAL) and an EPSS score of 0.93986, indicating a very high likelihood of exploitation, this vulnerability poses a severe risk. While not yet listed in CISA's KEV catalog, exploit intelligence shows available Nuclei templates and significant community discussion, with media coverage confirming active targeting by hackers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.9.6CPE matchmatch criteria | cpe:2.3:a:apache:rocketmq:*:*:*:*:*:*:*:* | ||
>= 5.0.0, <= 5.1.1CPE matchmatch criteria | cpe:2.3:a:apache:rocketmq:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.