CVE-2023-3494
Last modified
CVE-2023-3494 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. The fwctl driver implements a state machine which is executed when a bhyve guest accesses certain x86 I/O ports. The interface lets the guest copy a string into a buffer resident in the bhyve process' memory. EPSS estimates a 0.22% chance of exploitation in the next 30 days.
Description
The fwctl driver implements a state machine which is executed when a bhyve guest accesses certain x86 I/O ports. The interface lets the guest copy a string into a buffer resident in the bhyve process' memory. A bug in the state machine implementation can result in a buffer overflowing when copying this string. Malicious, privileged software running in a guest VM can exploit the buffer overflow to achieve code execution on the host in the bhyve userspace process, which typically runs as root, mitigated by the capabilities assigned through the Capsicum sandbox available to the bhyve process.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Freebsd | Freebsd | 13.1 |
| Freebsd | Freebsd | 13.2 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-3494?
How severe is CVE-2023-3494?
How do I fix CVE-2023-3494?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-34933A stack overflow in the UpdateWanParams function of H3C Magi…7.5
- CVE-2023-34934A stack overflow in the Edit_BasicSSID_5G function of H3C Ma…7.5
- CVE-2023-34935A stack overflow in the AddWlanMacList function of H3C Magic…7.5
- CVE-2023-34936A stack overflow in the UpdateMacClone function of H3C Magic…7.5
- CVE-2023-34937A stack overflow in the UpdateSnat function of H3C Magic B1S…7.5
- CVE-2023-34939Onlyoffice Community Server before v12.5.2 was discovered to…9.8
- CVE-2023-34940Asus RT-N10LX Router v2.0.0.39 was discovered to contain a s…7.5
- CVE-2023-34941A stored cross-site scripting (XSS) vulnerability in the url…5.4
- CVE-2023-34942Asus RT-N10LX Router v2.0.0.39 was discovered to contain a s…7.5
- CVE-2023-34944An arbitrary file upload vulnerability in the /fileUpload.li…9.8
- CVE-2023-3495** UNSUPPORTED WHEN ASSIGNED ** Out-of-bounds Write vulnerab…7.8
- CVE-2023-34958Incorrect access control in Chamilo 1.11.* up to 1.11.18 all…4.3
Are you affected by CVE-2023-3494?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
