peter bassill · operator
$ cve CVE-2023-37265 JSON

CVE-2023-37265

9.8
CRITICAL · CVSS 3.1 · EPSS 7.4% (pctl 94)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

CasaOS is an open-source Personal Cloud system. Due to a lack of IP address verification an unauthenticated attackers can execute arbitrary commands as `root` on CasaOS instances. The problem was addressed by improving the detection of client IP addresses in `391dd7f`. This patch is part of CasaOS 0.4.4. Users should upgrade to CasaOS 0.4.4. If they can't, they should temporarily restrict access to CasaOS to untrusted users, for instance by not exposing it publicly.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS7.36% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-306
On CISA KEVno
Public exploitnone known
Published2023-07-17
Last modified2026-06-17

Affected (2)

VendorProduct
icewhalecasaos
icewhalecasaos-gateway

References

→ the Explorer  ·  watch your stack  ·  NVD