Lucene search

K
cveMitreCVE-2023-49933
HistoryDec 14, 2023 - 5:15 a.m.

CVE-2023-49933

2023-12-1405:15:08
CWE-924
mitre
web.nvd.nist.gov
39
cve-2023-49933
schedmd
slurm
communication channel
message integrity
rpc traffic
security vulnerability

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

AI Score

8.2

Confidence

High

EPSS

0.001

Percentile

22.7%

An issue was discovered in SchedMD Slurm 22.05.x, 23.02.x, and 23.11.x. There is Improper Enforcement of Message Integrity During Transmission in a Communication Channel. This allows attackers to modify RPC traffic in a way that bypasses message hash checks. The fixed versions are 22.05.11, 23.02.7, and 23.11.1.

Affected configurations

Nvd
Node
schedmdslurmRange22.0522.05.12
OR
schedmdslurmRange23.0223.02.7
OR
schedmdslurmMatch23.11-
OR
schedmdslurmMatch23.11rc1
VendorProductVersionCPE
schedmdslurm*cpe:2.3:a:schedmd:slurm:*:*:*:*:*:*:*:*
schedmdslurm23.11cpe:2.3:a:schedmd:slurm:23.11:-:*:*:*:*:*:*
schedmdslurm23.11cpe:2.3:a:schedmd:slurm:23.11:rc1:*:*:*:*:*:*

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

AI Score

8.2

Confidence

High

EPSS

0.001

Percentile

22.7%