← voltar
CVE-2023-46604criticalsob ataqueransomwareCWE-502

Apache ActiveMQ, Apache ActiveMQ Legacy OpenWire Module: Unbounded deserialization causes ActiveMQ to be vulnerable to a remote code execution (RCE) attack

100Vexday Risk Score

Corrija agora. Ela está sob exploração confirmada pelo CISA e tem exploit funcional público.

ssvc Actcvss 10epss 100%
da publicação à arma0 dias
Publicada no NVD27 de out.
1ª PoC26 de out.
metasploit27 de out.
CISA KEV+6d
probabilidade de exploração
100%top 1% das CVEs
exploração observada
simCISA + VulnCheck
64 exploit(s) público(s)
Ação exigida pela CISAprazo federal: 2023-11-23

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Pesquisado e redigido com IA a partir do advisory do fornecedor e de análises públicas, com as fontes acima. Confira sempre a versão corrigida no advisory oficial antes de agir.
The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to either a Java-based OpenWire broker or client to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause either the client or the broker (respectively) to instantiate any class on the classpath. Users are recommended to upgrade both brokers and clients to version 5.15.16, 5.16.7, 5.17.6, or 5.18.3 which fixes this issue.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:H/A:H
PoCs públicas encontradas64
githubgithub.com/SaumyajeetDas/CVE-2023-46604-RCE-Reverse-Shell-Apache-ActiveMQ126githubgithub.com/Catherines77/ActiveMQ-EXPtools77githubgithub.com/Arlenhiack/ActiveMQ-RCE-Exploit43githubgithub.com/evkl1d/CVE-2023-4660440githubgithub.com/trganda/ActiveMQ-RCE28githubgithub.com/duck-sec/CVE-2023-46604-ActiveMQ-RCE-pseudoshell18githubgithub.com/justdoit-cai/CVE-2023-46604-Apache-ActiveMQ-RCE-exp5githubgithub.com/vulncheck-oss/cve-2023-466044githubgithub.com/h3x3h0g/ActiveMQ-RCE-CVE-2023-46604-Write-up3githubgithub.com/NKeshawarz/CVE-2023-46604-RCE3githubgithub.com/LiritoShawshark/CVE-2023-46604_ActiveMQ_RCE_Recurrence2githubgithub.com/dcm2406/CVE-Lab2githubgithub.com/RockyDesigne/SSP-Assignment-3-RCEYouLater2githubgithub.com/mrpentst/CVE-2023-466042githubgithub.com/vaishnavucv/Project-Vuln-Detection-N-Mitigation_1011githubgithub.com/pulentoski/CVE-2023-466041githubgithub.com/skrkcb2/CVE-2023-466041githubgithub.com/stegano5/ExploitScript-CVE-2023-466041githubgithub.com/minhangxiaohui/ActiveMQ_CVE-2023-466041githubgithub.com/dcm2406/CVE-2023-466040githubgithub.com/vjayant93/CVE-2023-46604-POC0githubgithub.com/CrackerCat/ActiveMQ_RCE_Pro_Max0githubgithub.com/nitzanoligo/CVE-2023-46604-demo0githubgithub.com/Mudoleto/Broker_ApacheMQ0githubgithub.com/tomasmussi/activemq-cve-2023-466040githubgithub.com/thinkycx/activemq-rce-cve-2023-466040githubgithub.com/mranv/honeypot.rs0githubgithub.com/cuanh2333/CVE-2023-466040githubgithub.com/CCIEVoice2009/CVE-2023-466040githubgithub.com/pavanaa4k/CVE-2023-46604-LAB0githubgithub.com/sangrok-jeon/CVE-2023-46604-Analysis0githubgithub.com/mkdemir/activemq-lockbit-analysis0githubgithub.com/Navya240/intel471-threat-hunting-cve-2023-466040githubgithub.com/KlaasStessens/CVE-2023-466040githubgithub.com/trnguyen03/activemq-ids-ips-lab0githubgithub.com/REGGYRAIDER/CVE-2023-46604-RCE0githubgithub.com/aelshimony-cloud/OpenWire-CVE-2023-46604-Investigation0vulncheckvulncheck.com/xdb/ac860bc0b755não verificadovulncheckvulncheck.com/xdb/1e134f0874f8não verificadovulncheckvulncheck.com/xdb/5f38a93c3fe0não verificadovulncheckvulncheck.com/xdb/c01880ea274bnão verificadovulncheckvulncheck.com/xdb/2a263bac5fa9não verificadovulncheckvulncheck.com/xdb/90299d8578e8não verificadovulncheckvulncheck.com/xdb/7adf2c60412fnão verificadovulncheckvulncheck.com/xdb/c1ad06a8233fnão verificadovulncheckvulncheck.com/xdb/d6b987f7cb4cnão verificadovulncheckvulncheck.com/xdb/adc63f08a561não verificadovulncheckvulncheck.com/xdb/111d5aa9554fnão verificadovulncheckvulncheck.com/xdb/7d454efa423fnão verificadovulncheckvulncheck.com/xdb/f688c01da056não verificadovulncheckvulncheck.com/xdb/26ec274f11a6não verificadovulncheckvulncheck.com/xdb/bd01e441da28não verificadovulncheckvulncheck.com/xdb/cc4ca3b4d289não verificadovulncheckvulncheck.com/xdb/9c19a15a7306não verificadovulncheckvulncheck.com/xdb/9af52ad961cenão verificadovulncheckvulncheck.com/xdb/bf84564c744cnão verificadovulncheckvulncheck.com/xdb/e3eff001f1dbnão verificadocve_referencepacketstormsecurity.com/files/175676/Apache-ActiveMQ-Unauthenticated-Remote-Code-Execution.htmlnão verificadovulncheckvulncheck.com/xdb/453453dd752fnão verificadovulncheckvulncheck.com/xdb/f5d0e2739b8cnão verificadovulncheckvulncheck.com/xdb/8ce9f74afedcnão verificadovulncheckvulncheck.com/xdb/28c5231dc0c7não verificadovulncheckvulncheck.com/xdb/07dca85f6442não verificadovulncheckvulncheck.com/xdb/0462e934919bnão verificado
⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.