CRITICAL

CVE-2023-25826

CVSS v3

9.8

CRITICAL

EPSS Score

83.9%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

Due to insufficient validation of parameters passed to the legacy HTTP query API, it is possible to inject crafted OS commands into multiple parameters and execute malicious code on the OpenTSDB host system. This exploit exists due to an incomplete fix that was made when this vulnerability was previously disclosed as CVE-2020-35476. Regex validation that was implemented to restrict allowed input to the query API does not work as intended, allowing crafted commands to bypass validation.

Technical details

Published
5/3/2023

Frequently asked questions

What is CVE-2023-25826?

Due to insufficient validation of parameters passed to the legacy HTTP query API, it is possible to inject crafted OS commands into multiple parameters and execute malicious code on the OpenTSDB host system. This exploit exists due to an incomplete fix that was made when this vulnerability was previously disclosed as CVE-2020-35476. Regex validation that was implemented to restrict allowed input to the query API does not work as intended, allowing crafted commands to bypass validation.

Is CVE-2023-25826 actively exploited?

Active exploitation of CVE-2023-25826 has not been confirmed. The EPSS score is 83.9%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2023-25826?

CVE-2023-25826 has a CVSS v3 base score of 9.8 (CRITICAL severity).

Is CVE-2023-25826 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.