Shrubbery tac_plus 2.x, 3.x
Published May 16, 2024
9.8
CRITICALCVSS 3.1
EPSS 1.16%
Description
Shrubbery tac_plus 2.x, 3.x. and 4.x through F4.0.4.28 allows unauthenticated Remote Command Execution. The product allows users to configure authorization checks as shell commands through the tac_plus.cfg configuration file. These are executed when a client sends an authorization request with a username that has pre-authorization directives configured. However, it is possible to inject additional commands into these checks because strings from TACACS+ packets are used as command-line arguments. If the installation lacks a a pre-shared secret (there is no pre-shared secret by default), then the injection can be triggered without authentication. (The attacker needs to know a username configured to use a pre-authorization command.) NOTE: this is related to CVE-2023-45239 but the issue is in the original Shrubbery product, not Meta's fork.
Affected products
No data.
No data.
-
- Version 0StatusaffectedConstraints<=f_4.0.4.28
- Version
-
- Version 0StatusaffectedConstraints<=f_4.0.4.28
- Version
-
- Version 0StatusaffectedConstraints<=f_4.0.4.28
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Shrubbery | Tac Plus 2x | n/a |
| ||||||
| Shrubbery | Tac Plus 3x | n/a |
| ||||||
| Shrubbery | Tac Plus 4x | n/a |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
YesTechnical Impact
TotalDecision
n/aAssessed Aug 20, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2025–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (11 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 1.16% (0.01158) | 65.92th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.10% (0.01096) | 61.13th | v5 (v2026.06.15) |
| Mar 25, 2026 | 7.27% (0.07266) | 91.58th | v4 (v2025.03.14) |
| Nov 21, 2025 | 9.11% (0.09108) | 92.33th | v4 (v2025.03.14) |
| Nov 18, 2025 | 3.29% (0.03292) | 85.98th | v4 (v2025.03.14) |
| Oct 5, 2025 | 9.11% (0.09108) | 92.34th | v4 (v2025.03.14) |
| Jul 13, 2025 | 6.92% (0.06919) | 90.95th | v4 (v2025.03.14) |
| Jun 24, 2025 | 5.49% (0.05485) | 89.72th | v4 (v2025.03.14) |
| Apr 15, 2025 | 1.61% (0.01609) | 80.67th | v4 (v2025.03.14) |
| Mar 17, 2025 | 3.06% (0.03063) | 85.81th | v4 (v2025.03.14) |
| Feb 14, 2025 | 0.04% (0.00043) | 11.64th | v3 (v2023.03.01) |
References (1)
Change history (0)
No recorded changes yet.