CVE-2023-45239 is a critical remote code execution vulnerability affecting tac_plus, including versions used by Facebook and Fedora, due to insufficient input validation. An unauthenticated attacker can inject shell commands by manipulating username, remote address, or NAC address fields, leading to full compromise of the tac_plus server. While no public exploits or active exploitation are currently reported, its CVSS score of 9.8 and FAUCET Risk Score of 97/100 highlight its severe potential impact. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2023-10-05CPE matchmatch criteria | cpe:2.3:a:facebook:tac_plus:*:*:*:*:*:*:*:* | ||
39CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.