CVE-2023-46604 is a critical Remote Code Execution vulnerability affecting the Java OpenWire protocol marshaller in Apache ActiveMQ, Debian, and NetApp products. It allows unauthenticated remote attackers to execute arbitrary shell commands by manipulating serialized class types. With a CVSS score of 9.8 (Critical) and an EPSS score of 0.94436, this vulnerability poses a severe risk due to its network-based attack vector and low complexity. It is actively exploited in the wild, including by LockBit, DripDropper, TellYouThePass, HelloKitty, and Kinsing ransomware campaigns, with a Metasploit module publicly available and significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 5.15.16CPE matchmatch criteria | cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:* | ||
>= 5.16.0, < 5.16.7CPE matchmatch criteria | cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:* | ||
>= 5.17.0, < 5.17.6CPE matchmatch criteria | cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:* | ||
>= 5.18.0, < 5.18.3CPE matchmatch criteria | cpe:2.3:a:apache:activemq:*:*:*:*:*:*:*:* | ||
< 5.15.16CPE matchmatch criteria | cpe:2.3:a:apache:activemq_legacy_openwire_module:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2023-46604
Apr 1, 2024Remote Code Execution Vulnerability in Apache ActiveMQ
Nov 6, 2023Remote Code Execution Vulnerability in Apache ActiveMQ
Nov 6, 2023Remote Code Execution Vulnerability in Apache ActiveMQ
Nov 6, 2023Remote Code Execution Vulnerability in Apache ActiveMQ
Nov 6, 2023Remote Code Execution Vulnerability in Apache ActiveMQ
Nov 6, 2023Remote Code Execution Vulnerability in Apache ActiveMQ
Nov 6, 2023Remote Code Execution Vulnerability in Apache ActiveMQ
Nov 6, 2023Remote Code Execution Vulnerability in Apache ActiveMQ
Nov 6, 2023Apache ActiveMQ is vulnerable to Remote Code Execution
Oct 27, 2023activemq-openwire: OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack
Oct 27, 2023