Lucene search

K
ubuntucveUbuntu.comUB:CVE-2023-49933
HistoryDec 14, 2023 - 12:00 a.m.

CVE-2023-49933

2023-12-1400:00:00
ubuntu.com
ubuntu.com
20
cve-2023-49933
schedmd
slurm
communication channel
rpc traffic
message integrity

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

AI Score

6.9

Confidence

Low

EPSS

0.001

Percentile

22.7%

An issue was discovered in SchedMD Slurm 22.05.x, 23.02.x, and 23.11.x.
There is Improper Enforcement of Message Integrity During Transmission in a
Communication Channel. This allows attackers to modify RPC traffic in a way
that bypasses message hash checks. The fixed versions are 22.05.11,
23.02.7, and 23.11.1.

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

AI Score

6.9

Confidence

Low

EPSS

0.001

Percentile

22.7%