CVE-2023-49933
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Dec 14, 2023
Updated: Jan 3, 2024
CWE ID 924
Summary
CVE-2023-49933 is a vulnerability affecting SchedMD Slurm versions 22.05.x, 23.02.x, and 23.11.x. The issue involves a lack of message integrity enforcement during transmission in a communication channel. This weakness enables attackers to manipulate RPC traffic undetected, bypassing message hash checks. The affected systems should be updated to the fixed versions: 22.05.11, 23.02.7, and 23.11.1.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Schedmd Slurm
Affected Vendors
- SchedMD