CVE-2023-43632 is a critical stack-based buffer overflow vulnerability affecting the Linux Foundation Edge Virtualization Engine (EVE) VTPM server. The server, listening on port 8877, improperly handles incoming data by allocating a fixed-size stack buffer based on a user-supplied length, allowing an authenticated attacker to send an oversized payload. This can lead to a denial of service by crashing the system or, more critically, enable arbitrary code execution with the highly privileged "vtpm_server" process. With a CVSS score of 9.9 (Critical), the vulnerability is easily exploitable over the network with low attack complexity and no user interaction required. While there is no evidence of active exploitation, public exploit code, or Metasploit/Nuclei modules, the vulnerability has garnered significant community discussion, indicating awareness and potential future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.0.0, < 9.5.0CPE matchmatch criteria | cpe:2.3:o:linuxfoundation:edge_virtualization_engine:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.