CVE-2023-34254
GLPI Agent vulnerability analysis and mitigation

Overview

The GLPI Agent, a generic management agent, contained a critical vulnerability (CVE-2023-34254) prior to version 1.5. The vulnerability was discovered in the remoteinventory task when running against Unix platforms using SSH command mode. The issue was disclosed on June 21, 2023, and affects all versions of GLPI Agent before version 1.5 (NIST NVD, GitHub Advisory).

Technical details

The vulnerability is classified as a command injection flaw (CWE-78) with a CVSS v3.1 base score of 7.2 HIGH (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H). The issue occurs when the agent runs the remoteinventory task against a Unix platform using SSH command mode, where an administrator user on the remote system can inject commands into a specific workflow that the agent executes with its privileges (NIST NVD).

Impact

The vulnerability has significant impact potential. If the GLPI Agent is running with administrative privileges, a malicious user could gain elevated privileges on the computer where GLPI Agent is running. Additionally, attackers could potentially disclose all remote access configurations that the agent uses for the remoteinventory task (GitHub Advisory).

Exploitability

The vulnerability requires an attacker to have administrator access on the remote Unix system being inventoried. While this presents a high privilege requirement, the attack complexity is considered low once these privileges are obtained (NIST NVD).

Mitigation and workarounds

The primary mitigation is to upgrade to GLPI Agent version 1.5 or later. For users unable to upgrade immediately, there are two workarounds: 1) Force remoteinventory mode to libssh2 by adding ?mode=libssh2 to the remote URL, or 2) Disable the vulnerable code by setting no-category configuration to process,virtualmachine,video,drive,database,storage (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related GLPI Agent vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2024-28241HIGH7.8
  • GLPI Agent logoGLPI Agent
  • cpe:2.3:a:glpi-project:glpi_agent
NoYesApr 25, 2024
CVE-2024-28240HIGH7.8
  • GLPI Agent logoGLPI Agent
  • cpe:2.3:a:glpi-project:glpi_agent
NoYesApr 25, 2024
CVE-2023-34254HIGH7.2
  • GLPI Agent logoGLPI Agent
  • glpi
NoYesJun 23, 2023

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management