CVE-2023-25690
published 2023-03-07CVE-2023-25690: Some mod_proxy configurations on Apache HTTP Server versions 2.4.0 through 2.4.55 allow a HTTP Request Smuggling attack. Configurations are affected when…
PriorityP189critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
ITWEXPLOITVulnCheck KEVInitial access
Exploited in the wild
EPSS
83.77%
99.7th percentile
Some mod_proxy configurations on Apache HTTP Server versions 2.4.0 through 2.4.55 allow a HTTP Request Smuggling attack.
Configurations are affected when mod_proxy is enabled along with some form of RewriteRule
or ProxyPassMatch in which a non-specific pattern matches
some portion of the user-supplied request-target (URL) data and is then
re-inserted into the proxied request-target using variable
substitution. For example, something like:
RewriteEngine on
RewriteRule "^/here/(.*)" "http://example.com:8080/elsewhere?$1"; [P]
ProxyPassReverse /here/ http://example.com:8080/
Request splitting/smuggling could result in bypass of access controls in the proxy server, proxying unintended URLs to existing origin servers, and cache poisoning. Users are recommended to update to at least version 2.4.56 of Apache HTTP Server.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | http_server | 2.4.0 – 2.4.55 | — |
| apache_software_foundation | apache_http_server | 2.4.0 – 2.4.55 | — |
| debian | apache2 | < apache2 2.4.56-1 (bookworm) | apache2 2.4.56-1 (bookworm) |
| msrc | azl3_mod_http2_2.0.29-3_on_azure_linux_3.0 | — | — |
| msrc | cbl2_httpd_2.4.56-1_on_cbl_mariner_2.0 | — | — |
| msrc | cm1_httpd_2.4.56-1_on_cbl_mariner_1.0 | — | — |
| paloalto | pan-os | — | — |
Detection & IOCsextracted from sources · hover to see the quote
- →HTTP Request Smuggling via mod_proxy when RewriteRule or ProxyPassMatch uses a non-specific capture group that re-inserts user-supplied request-target data into the proxied URL via variable substitution ↗
- →Canonical vulnerable config pattern to detect in Apache configs: RewriteRule with open-ended capture (.*) passed as query parameter to a proxied backend — e.g. RewriteRule "^/here/(.*)" "http://example.com:8080/elsewhere?$1" [P] ↗
- →Attack outcomes to hunt for in proxy/access logs: access control bypass, unexpected URLs forwarded to origin servers, and cache poisoning artifacts ↗
- →Affected Apache HTTP Server versions are 2.4.0 through 2.4.55; presence of these versions with mod_proxy enabled warrants investigation ↗
- ·Vulnerability is only exploitable when mod_proxy is enabled AND a RewriteRule or ProxyPassMatch with a non-specific (open-ended) capture pattern re-inserts user-controlled data into the proxied request-target via variable substitution. Not all mod_proxy deployments are affected. ↗
- ·Red Hat Enterprise Linux 6 httpd package is listed as Not Affected; Red Hat JBoss EAP 6 httpd22 is out of support scope — detections should be scoped accordingly. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vulncheck9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_msrc9.8CRITICAL
vendor_oracle9.8CRITICAL
vendor_redhat9.8CRITICAL
vendor_ubuntu9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Festo Didactic SE MES PC
cisa_ics·2026-01-27·CVSS 7.5
[HIGH] Festo Didactic SE MES PC
ICS Advisory
##
Festo Didactic SE MES PC
Release DateJanuary 27, 2026
Alert CodeICSA-26-027-02
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## Summary
MES PCs shipped with Windows 10 come pre-installed with XAMPP. XAMPP is a bundle of third-party open-source applications including the Apache HTTP Server, the MariaDB database and more. From time to time, vulnerabilities in these applications are discovered. These are fixed in newer versions of XAMPP by updating the bundled applications. MES PCs shipped with Windows 10 include a copy of XAMPP which contains around 140 such vulnerabilities listed in this advisory. They can be fixed by replacing XAMPP with Festo Didactic's Factory Control Panel application.
The
CISA ICS
Hitachi Energy Service Suite
cisa_ics·2025-05-13·CVSS 9.8
[CRITICAL] Hitachi Energy Service Suite
ICS Advisory
##
Hitachi Energy Service Suite
Release DateMay 13, 2025
Alert CodeICSA-25-133-01
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 9.3
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Hitachi Energy
- Equipment: Service Suite
- Vulnerabilities: Use of Less Trusted Source, Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), Integer Overflow or Wraparound, Out-of-bounds Write, Allocation of Resources Without Limits or Throttling, Exposure of Sensitive Information to an Unauthorized Actor, Memory Allocation with Excessive Size Value, Out-of-bounds Read, Uncontrolled Resource Consumption, Improper Resource Shutdown or Re
CISA ICS
ABB M2M Gateway
cisa_ics·2025-04-15
ABB M2M Gateway
ICS Advisory
##
ABB M2M Gateway
Release DateApril 15, 2025
Alert CodeICSA-25-105-08
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 8.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: ABB
- Equipment: M2M Gateway
- Vulnerabilities: Integer Overflow or Wraparound, Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling'), Unquoted Search Path or Element, Untrusted Search Path, Use After Free, Out-of-bounds Write, Buffer Copy without Checking Size of Input ('Classic Buffer Overflow'), Missing Release of Memory after Effective Lifetime, Allocation of Resources Without Limits or Throttling, Improper Privilege Management, Improper Limitati
CISA ICS
Siemens SINEC NMS
cisa_ics·2024-02-15
Siemens SINEC NMS
ICS Advisory
##
Siemens SINEC NMS
Release DateFebruary 15, 2024
Alert CodeICSA-24-046-15
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SINEC NMS
- Vulnerabilities: Out-of-bounds Read, Inadequate Encryption Strength, Double Free, Use After Free, NULL Pointer Dereference, Improper Input Validation, Missing Encryption of Sensitive Data, Allocation of Resources Wit
CISA ICS
Siemens SCALANCE XCM-/XRM-300
cisa_ics·2024-02-15
Siemens SCALANCE XCM-/XRM-300
ICS Advisory
##
Siemens SCALANCE XCM-/XRM-300
Release DateFebruary 15, 2024
Alert CodeICSA-24-046-11
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SCALANCE XCM-/XRM-300
- Vulnerabilities: Out-of-bounds Write, Incorrect Type Conversion or Cast, Improper Verification of Cryptographic Signature, Improper Access Control, Improper Authentication, Missing Encryption
Palo Alto
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2024-02-14·CVSS 9.8
CVE-2017-18342 [CRITICAL] PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2024-0001 Informational Bulletin: Impact of OSS CVEs in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2017-18342, CVE-2017-8923, CVE-2017-9120, CVE-2019-1551, CVE-2019-16865, CVE-2019-16905, CVE-2019-19523, CVE-2019-19528, CVE-2019-19911, CVE-2020-0404, CVE-2020-0431, CVE-2020-0466, CVE-2020-10379, CVE-2020-11538, CVE-2020-11608, CVE-2020-12114, CVE-2020-12321, CVE-2020-12362, CVE-2020-12363, CVE-2020-12364, CVE-2020-13757, CVE-2020-14314, CVE-2020-14351, CVE-2020-15778, CVE-2020-1967, CVE-2020-24394, CVE-2020-24504, CVE-2020-25211, CVE-2020-25212, CVE-2020-25284, CVE-2020-25285, CVE-2020-25717, CVE-2020-26541, CVE-2020-2715
Oracle
Oracle Oracle Hyperion Risk Matrix: Installation and Configuration (Apache HTTP Server) — CVE-2023-25690
vendor_oracle·2023-10-15·CVSS 9.8
CVE-2023-25690 [CRITICAL] Oracle Oracle Hyperion Risk Matrix: Installation and Configuration (Apache HTTP Server) — CVE-2023-25690
Oracle Oracle Hyperion Risk Matrix: Installation and Configuration (Apache HTTP Server) vulnerability
CVE: CVE-2023-25690
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuoct2023 (OCT 2023)
Oracle
Oracle Oracle Enterprise Manager Risk Matrix: Networking (Apache HTTP Server) — CVE-2023-25690
vendor_oracle·2023-07-15·CVSS 9.8
CVE-2023-25690 [CRITICAL] Oracle Oracle Enterprise Manager Risk Matrix: Networking (Apache HTTP Server) — CVE-2023-25690
Oracle Oracle Enterprise Manager Risk Matrix: Networking (Apache HTTP Server) vulnerability
CVE: CVE-2023-25690
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2023 (JUL 2023)
Oracle
Oracle Oracle Communications Risk Matrix: FEServer (Apache HTTP Server) — CVE-2023-25690
vendor_oracle·2023-04-15·CVSS 9.8
CVE-2023-25690 [CRITICAL] Oracle Oracle Communications Risk Matrix: FEServer (Apache HTTP Server) — CVE-2023-25690
Oracle Oracle Communications Risk Matrix: FEServer (Apache HTTP Server) vulnerability
CVE: CVE-2023-25690
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
Ubuntu
Apache HTTP Server vulnerability
vendor_ubuntu·2023-03-22·CVSS 9.8
CVE-2023-25690 [CRITICAL] Apache HTTP Server vulnerability
Title: Apache HTTP Server vulnerability
Summary: Apache HTTP Server could allow unintended access to network services.
USN-5942-1 fixed vulnerabilities in Apache HTTP Server. This update
provides the corresponding update for CVE-2023-25690 for Ubuntu 16.04 ESM.
Original advisory details:
Lars Krapf discovered that the Apache HTTP Server mod_proxy module
incorrectly handled certain configurations. A remote attacker could
possibly use this issue to perform an HTTP Request Smuggling attack.
(CVE-2023-25690)
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
Apache HTTP Server: HTTP request splitting with mod_rewrite and mod_proxy
vendor_msrc·2023-03-14·CVSS 9.8
CVE-2023-25690 [CRITICAL] CWE-444 Apache HTTP Server: HTTP request splitting with mod_rewrite and mod_proxy
Apache HTTP Server: HTTP request splitting with mod_rewrite and mod_proxy
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to reflect this.
Mariner: Mariner
apache: apache
Customer Action Required: Yes
Remediation: CBL-Mariner Releases
Refe
Ubuntu
Apache HTTP Server vulnerabilities
vendor_ubuntu·2023-03-09·CVSS 9.8
CVE-2023-27522 [CRITICAL] Apache HTTP Server vulnerabilities
Title: Apache HTTP Server vulnerabilities
Summary: Several security issues were fixed in Apache HTTP Server.
Lars Krapf discovered that the Apache HTTP Server mod_proxy module
incorrectly handled certain configurations. A remote attacker could
possibly use this issue to perform an HTTP Request Smuggling attack.
(CVE-2023-25690)
Dimas Fariski Setyawan Putra discovered that the Apache HTTP Server
mod_proxy_uwsgi module incorrectly handled certain special characters. A
remote attacker could possibly use this issue to perform an HTTP Request
Smuggling attack. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04
LTS, and Ubuntu 22.10. (CVE-2023-27522)
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
httpd: HTTP request splitting with mod_rewrite and mod_proxy
vendor_redhat·2023-03-07·CVSS 9.8
CVE-2023-25690 [CRITICAL] CWE-113 httpd: HTTP request splitting with mod_rewrite and mod_proxy
httpd: HTTP request splitting with mod_rewrite and mod_proxy
Some mod_proxy configurations on Apache HTTP Server versions 2.4.0 through 2.4.55 allow a HTTP Request Smuggling attack.
Configurations are affected when mod_proxy is enabled along with some form of RewriteRule
or ProxyPassMatch in which a non-specific pattern matches
some portion of the user-supplied request-target (URL) data and is then
re-inserted into the proxied request-target using variable
substitution. For example, something like:
RewriteEngine on
RewriteRule "^/here/(.*)" "http://example.com:8080/elsewhere?$1"; [P]
ProxyPassReverse /here/ http://example.com:8080/
Request splitting/smuggling could result in bypass of access controls in the proxy server, proxying unintended URLs to existing origin servers, and cache poiso
Debian
CVE-2023-25690: apache2 - Some mod_proxy configurations on Apache HTTP Server versions 2.4.0 through 2.4.5...
vendor_debian·2023·CVSS 9.8
CVE-2023-25690 [CRITICAL] CVE-2023-25690: apache2 - Some mod_proxy configurations on Apache HTTP Server versions 2.4.0 through 2.4.5...
Some mod_proxy configurations on Apache HTTP Server versions 2.4.0 through 2.4.55 allow a HTTP Request Smuggling attack. Configurations are affected when mod_proxy is enabled along with some form of RewriteRule or ProxyPassMatch in which a non-specific pattern matches some portion of the user-supplied request-target (URL) data and is then re-inserted into the proxied request-target using variable substitution. For example, something like: RewriteEngine on RewriteRule "^/here/(.*)" "http://example.com:8080/elsewhere?$1"; [P] ProxyPassReverse /here/ http://example.com:8080/ Request splitting/smuggling could result in bypass of access controls in the proxy server, proxying unintended URLs to existing origin servers, and cache poisoning. Users are recommended to update to at least version 2.4.
OSV
apache2 vulnerability
osv·2023-03-22·CVSS 9.8
CVE-2023-25690 [CRITICAL] apache2 vulnerability
apache2 vulnerability
USN-5942-1 fixed vulnerabilities in Apache HTTP Server. This update
provides the corresponding update for CVE-2023-25690 for Ubuntu 16.04 ESM.
Original advisory details:
Lars Krapf discovered that the Apache HTTP Server mod_proxy module
incorrectly handled certain configurations. A remote attacker could
possibly use this issue to perform an HTTP Request Smuggling attack.
(CVE-2023-25690)
OSV
apache2 vulnerabilities
osv·2023-03-09·CVSS 9.8
CVE-2023-25690 [CRITICAL] apache2 vulnerabilities
apache2 vulnerabilities
Lars Krapf discovered that the Apache HTTP Server mod_proxy module
incorrectly handled certain configurations. A remote attacker could
possibly use this issue to perform an HTTP Request Smuggling attack.
(CVE-2023-25690)
Dimas Fariski Setyawan Putra discovered that the Apache HTTP Server
mod_proxy_uwsgi module incorrectly handled certain special characters. A
remote attacker could possibly use this issue to perform an HTTP Request
Smuggling attack. This issue only affected Ubuntu 20.04 LTS, Ubuntu 22.04
LTS, and Ubuntu 22.10. (CVE-2023-27522)
GHSA
GHSA-wc6r-9c75-44gq: Some mod_proxy configurations on Apache HTTP Server versions 2
ghsa_unreviewed·2023-03-07
CVE-2023-25690 [CRITICAL] CWE-444 GHSA-wc6r-9c75-44gq: Some mod_proxy configurations on Apache HTTP Server versions 2
Some mod_proxy configurations on Apache HTTP Server versions 2.4.0 through 2.4.55 allow a HTTP Request Smuggling attack. Configurations are affected when mod_proxy is enabled along with some form of RewriteRule or ProxyPassMatch in which a non-specific pattern matches some portion of the user-supplied request-target (URL) data and is then re-inserted into the proxied request-target using variable substitution. For example, something like: RewriteEngine on RewriteRule "^/here/(.*)" "http://example.com:8080/elsewhere?$1"; [P] ProxyPassReverse /here/ http://example.com:8080/ Request splitting/smuggling could result in bypass of access controls in the proxy server, proxying unintended URLs to existing origin servers, and cache poisoning. Users are recommended to update to at least version 2.4.
OSV
CVE-2023-25690: Some mod_proxy configurations on Apache HTTP Server versions 2
osv·2023-03-07·CVSS 9.8
CVE-2023-25690 [CRITICAL] CVE-2023-25690: Some mod_proxy configurations on Apache HTTP Server versions 2
Some mod_proxy configurations on Apache HTTP Server versions 2.4.0 through 2.4.55 allow a HTTP Request Smuggling attack.
Configurations are affected when mod_proxy is enabled along with some form of RewriteRule
or ProxyPassMatch in which a non-specific pattern matches
some portion of the user-supplied request-target (URL) data and is then
re-inserted into the proxied request-target using variable
substitution. For example, something like:
RewriteEngine on
RewriteRule "^/here/(.*)" "http://example.com:8080/elsewhere?$1"; [P]
ProxyPassReverse /here/ http://example.com:8080/
Request splitting/smuggling could result in bypass of access controls in the proxy server, proxying unintended URLs to existing origin servers, and cache poisoning. Users are recommended to update to at least versio
OSV
CVE-2023-25690: Some mod_proxy configurations on Apache HTTP Server versions 2
osv·2023-03-07·CVSS 9.8
CVE-2023-25690 [CRITICAL] CVE-2023-25690: Some mod_proxy configurations on Apache HTTP Server versions 2
Some mod_proxy configurations on Apache HTTP Server versions 2.4.0 through 2.4.55 allow a HTTP Request Smuggling attack. Configurations are affected when mod_proxy is enabled along with some form of RewriteRule or ProxyPassMatch in which a non-specific pattern matches some portion of the user-supplied request-target (URL) data and is then re-inserted into the proxied request-target using variable substitution. For example, something like: RewriteEngine on RewriteRule "^/here/(.*)" "http://example.com:8080/elsewhere?$1"; [P] ProxyPassReverse /here/ http://example.com:8080/ Request splitting/smuggling could result in bypass of access controls in the proxy server, proxying unintended URLs to existing origin servers, and cache poisoning. Users are recommended to update to at least version 2.4.
VulnCheck
Apache HTTP Server Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
vulncheck·2023·CVSS 9.8
CVE-2023-25690 [CRITICAL] Apache HTTP Server Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
Apache HTTP Server Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
Some mod_proxy configurations on Apache HTTP Server versions 2.4.0 through 2.4.55 allow a HTTP Request Smuggling attack.
Configurations are affected when mod_proxy is enabled along with some form of RewriteRule
or ProxyPassMatch in which a non-specific pattern matches
some portion of the user-supplied request-target (URL) data and is then
re-inserted into the proxied request-target using variable
substitution. For example, something like:
RewriteEngine on
RewriteRule "^/here/(.*)" "http://example.com:8080/elsewhere?$1"; [P]
ProxyPassReverse /here/ http://example.com:8080/
Request splitting/smuggling could result in bypass of access controls in the proxy server, proxying unintended URL
Suricata
ET WEB_SPECIFIC_APPS Apache 2.4.0 -> 2.4.55 HTTP Smuggling Attempt M7 (CVE-2023-25690)
suricata·2024-10-03·CVSS 9.8
CVE-2023-25690 [CRITICAL] ET WEB_SPECIFIC_APPS Apache 2.4.0 -> 2.4.55 HTTP Smuggling Attempt M7 (CVE-2023-25690)
ET WEB_SPECIFIC_APPS Apache 2.4.0 -> 2.4.55 HTTP Smuggling Attempt M7 (CVE-2023-25690)
Rule: alert http any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET WEB_SPECIFIC_APPS Apache 2.4.0 -> 2.4.55 HTTP Smuggling Attempt M7 (CVE-2023-25690)"; flow:established,to_server; http.request_body; content:"OPTIONS|20 2f|"; startswith; fast_pattern; reference:url,attackerkb.com/topics/0Uka1VHsPO/cve-2023-25690/rapid7-analysis; reference:cve,2023-25690; classtype:web-application-attack; sid:2056429; rev:1; metadata:affected_product Apache_HTTP_server, attack_target Server, created_at 2024_10_03, cve CVE_2023_25690, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, updated_at 2024_10_03, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_te
Suricata
ET WEB_SPECIFIC_APPS Apache 2.4.0 -> 2.4.55 HTTP Smuggling Attempt M5 (CVE-2023-25690)
suricata·2024-10-03·CVSS 9.8
CVE-2023-25690 [CRITICAL] ET WEB_SPECIFIC_APPS Apache 2.4.0 -> 2.4.55 HTTP Smuggling Attempt M5 (CVE-2023-25690)
ET WEB_SPECIFIC_APPS Apache 2.4.0 -> 2.4.55 HTTP Smuggling Attempt M5 (CVE-2023-25690)
Rule: alert http any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET WEB_SPECIFIC_APPS Apache 2.4.0 -> 2.4.55 HTTP Smuggling Attempt M5 (CVE-2023-25690)"; flow:established,to_server; http.request_body; content:"DELETE|20 2f|"; startswith; fast_pattern; reference:url,attackerkb.com/topics/0Uka1VHsPO/cve-2023-25690/rapid7-analysis; reference:cve,2023-25690; classtype:web-application-attack; sid:2056427; rev:1; metadata:affected_product Apache_HTTP_server, attack_target Server, created_at 2024_10_03, cve CVE_2023_25690, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, updated_at 2024_10_03, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_tec
Suricata
ET WEB_SPECIFIC_APPS Apache 2.4.0 -> 2.4.55 HTTP Smuggling Attempt M6 (CVE-2023-25690)
suricata·2024-10-03·CVSS 9.8
CVE-2023-25690 [CRITICAL] ET WEB_SPECIFIC_APPS Apache 2.4.0 -> 2.4.55 HTTP Smuggling Attempt M6 (CVE-2023-25690)
ET WEB_SPECIFIC_APPS Apache 2.4.0 -> 2.4.55 HTTP Smuggling Attempt M6 (CVE-2023-25690)
Rule: alert http any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET WEB_SPECIFIC_APPS Apache 2.4.0 -> 2.4.55 HTTP Smuggling Attempt M6 (CVE-2023-25690)"; flow:established,to_server; http.request_body; content:"CONNECT|20 2f|"; startswith; fast_pattern; reference:url,attackerkb.com/topics/0Uka1VHsPO/cve-2023-25690/rapid7-analysis; reference:cve,2023-25690; classtype:web-application-attack; sid:2056428; rev:1; metadata:affected_product Apache_HTTP_server, attack_target Server, created_at 2024_10_03, cve CVE_2023_25690, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, updated_at 2024_10_03, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_te
Suricata
ET WEB_SPECIFIC_APPS Apache 2.4.0 -> 2.4.55 HTTP Smuggling Attempt M3 (CVE-2023-25690)
suricata·2024-10-03·CVSS 9.8
CVE-2023-25690 [CRITICAL] ET WEB_SPECIFIC_APPS Apache 2.4.0 -> 2.4.55 HTTP Smuggling Attempt M3 (CVE-2023-25690)
ET WEB_SPECIFIC_APPS Apache 2.4.0 -> 2.4.55 HTTP Smuggling Attempt M3 (CVE-2023-25690)
Rule: alert http any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET WEB_SPECIFIC_APPS Apache 2.4.0 -> 2.4.55 HTTP Smuggling Attempt M3 (CVE-2023-25690)"; flow:established,to_server; http.request_body; content:"HEAD|20 2f|"; startswith; fast_pattern; reference:url,attackerkb.com/topics/0Uka1VHsPO/cve-2023-25690/rapid7-analysis; reference:cve,2023-25690; classtype:web-application-attack; sid:2056425; rev:1; metadata:affected_product Apache_HTTP_server, attack_target Server, created_at 2024_10_03, cve CVE_2023_25690, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, updated_at 2024_10_03, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_techn
Suricata
ET WEB_SPECIFIC_APPS Apache 2.4.0 -> 2.4.55 HTTP Smuggling Attempt M1 (CVE-2023-25690)
suricata·2024-10-03·CVSS 9.8
CVE-2023-25690 [CRITICAL] ET WEB_SPECIFIC_APPS Apache 2.4.0 -> 2.4.55 HTTP Smuggling Attempt M1 (CVE-2023-25690)
ET WEB_SPECIFIC_APPS Apache 2.4.0 -> 2.4.55 HTTP Smuggling Attempt M1 (CVE-2023-25690)
Rule: alert http any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET WEB_SPECIFIC_APPS Apache 2.4.0 -> 2.4.55 HTTP Smuggling Attempt M1 (CVE-2023-25690)"; flow:established,to_server; http.request_body; content:"GET|20 2f|"; startswith; fast_pattern; reference:url,attackerkb.com/topics/0Uka1VHsPO/cve-2023-25690/rapid7-analysis; reference:cve,2023-25690; classtype:web-application-attack; sid:2056423; rev:1; metadata:affected_product Apache_HTTP_server, attack_target Server, created_at 2024_10_03, cve CVE_2023_25690, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, updated_at 2024_10_03, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_techni
Suricata
ET WEB_SPECIFIC_APPS Apache 2.4.0 -> 2.4.55 HTTP Smuggling Attempt M4 (CVE-2023-25690)
suricata·2024-10-03·CVSS 9.8
CVE-2023-25690 [CRITICAL] ET WEB_SPECIFIC_APPS Apache 2.4.0 -> 2.4.55 HTTP Smuggling Attempt M4 (CVE-2023-25690)
ET WEB_SPECIFIC_APPS Apache 2.4.0 -> 2.4.55 HTTP Smuggling Attempt M4 (CVE-2023-25690)
Rule: alert http any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET WEB_SPECIFIC_APPS Apache 2.4.0 -> 2.4.55 HTTP Smuggling Attempt M4 (CVE-2023-25690)"; flow:established,to_server; http.request_body; content:"PUT|20 2f|"; startswith; fast_pattern; reference:url,attackerkb.com/topics/0Uka1VHsPO/cve-2023-25690/rapid7-analysis; reference:cve,2023-25690; classtype:web-application-attack; sid:2056426; rev:1; metadata:affected_product Apache_HTTP_server, attack_target Server, created_at 2024_10_03, cve CVE_2023_25690, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, updated_at 2024_10_03, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_techni
Suricata
ET WEB_SPECIFIC_APPS Apache 2.4.0 -> 2.4.55 HTTP Smuggling Attempt M2 (CVE-2023-25690)
suricata·2024-10-03·CVSS 9.8
CVE-2023-25690 [CRITICAL] ET WEB_SPECIFIC_APPS Apache 2.4.0 -> 2.4.55 HTTP Smuggling Attempt M2 (CVE-2023-25690)
ET WEB_SPECIFIC_APPS Apache 2.4.0 -> 2.4.55 HTTP Smuggling Attempt M2 (CVE-2023-25690)
Rule: alert http any any -> [$HOME_NET,$HTTP_SERVERS] any (msg:"ET WEB_SPECIFIC_APPS Apache 2.4.0 -> 2.4.55 HTTP Smuggling Attempt M2 (CVE-2023-25690)"; flow:established,to_server; http.request_body; content:"POST|20 2f|"; startswith; fast_pattern; reference:url,attackerkb.com/topics/0Uka1VHsPO/cve-2023-25690/rapid7-analysis; reference:cve,2023-25690; classtype:web-application-attack; sid:2056424; rev:1; metadata:affected_product Apache_HTTP_server, attack_target Server, created_at 2024_10_03, cve CVE_2023_25690, deployment Perimeter, deployment Internal, confidence Medium, signature_severity Major, tag Exploit, updated_at 2024_10_03, mitre_tactic_id TA0001, mitre_tactic_name Initial_Access, mitre_techn
No public exploits indexed.
arXiv
Plug. Play. Persist. Inside a Ready-to-Go Havoc C2 Infrastructure
arxiv_fulltext·2025-06-30·CVSS 9.8
[CRITICAL] Plug. Play. Persist. Inside a Ready-to-Go Havoc C2 Infrastructure
titlepage
*1cm
Plug. Play. Persist. Inside a Ready-to-Go Havoc C2 Infrastructure \ 1cm]
Alessio Di Santo ([email protected])
Università degli Studi dell’Aquila, L’Aquila, Abruzzo, Italy
Date: July 1,2025
!60 "Non videmus ea quae mox futura sunt" \ 0.5cm]
!60(We do not see the things that will soon be) — Marcus Tullius Cicero
titlepage
## Executive Summary
This analysis focuses on a single Azure-hosted Virtual Machine at 52.230.23[.]114 that the adversary converted into an all-in-one delivery, staging and Command-and-Control node. The host advertises an out-of-date Apache 2.4.52 instance whose open directory exposes phishing lures, PowerShell loaders, Reflective Shell-Code, compiled Havoc Demon implants and a toolbox of lateral-movement binaries; the same server als
arXiv
CyLens: Towards Reinventing Cyber Threat Intelligence in the Paradigm of Agentic Large Language Models
arxiv_fulltext·2025-04-16
CyLens: Towards Reinventing Cyber Threat Intelligence in the Paradigm of Agentic Large Language Models
: Towards Reinventing Cyber Threat Intelligence in the Paradigm of Agentic Large Language Models
Xiaoqun Liu
Stony Brook University
Stony Brook, NY, USA
[email protected]
Jiacheng Liang*
* Xiaoqun Liu and Jiacheng Liang contributed equally to this work.
Stony Brook University
Stony Brook, NY, USA
[email protected]
Qiben Yan
Michigan State University
East Lansing, MI, USA
[email protected]
Jiyong Jang
IBM Research
Yorktown Heights, NY, USA
[email protected]
Sicheng Mao
Google
New York City, NY, USA
[email protected]
Muchao Ye
The University of Iowa
Iowa City, IA, USA
[email protected]
Jinyuan Jia
Pennsylvania State University
State College, PA, USA
[email protected]
Zhaohan Xi
Binghamton University
Vestal, NY, USA
[email protected]
## Abstract
The exponential g
Qualys
Oracle Patch Tuesday, July 2023 Security Update Review
blogs_qualys·2023-07-19
Oracle Patch Tuesday, July 2023 Security Update Review
## Table of Contents
Qualys QID Coverage
Notable Oracle Vulnerabilities Patched
Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
Rapid Response with Patch Management (PM)
Oracle has released its third quarterly edition of Critical Patch Update, which contains a group of patches for 508 security vulnerabilities. Some of the vulnerabilities addressed this month impact more than one product. These patches address vulnerabilities in Oracle code and third-party components included in Oracle products.
During Q3 2023 Oracle Critical Patch Update, the Oracle Financial Services Applications received the highest number of 147 patches, constituting 29% of the total patches released. Oracle Communications and Oracle Fusion Middleware followed, with
Qualys
Oracle Patch Tuesday, July 2023 Security Update Review | Qualys
blogs_qualys·2023-07-19
Oracle Patch Tuesday, July 2023 Security Update Review | Qualys
#### Table of Contents
- Qualys QID Coverage
- Notable Oracle Vulnerabilities Patched
- Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
- Rapid Response with Patch Management (PM)
Oracle has released its third quarterly edition of Critical Patch Update, which contains a group of patches for 508 security vulnerabilities. Some of the vulnerabilities addressed this month impact more than one product. These patches address vulnerabilities in Oracle code and third-party components included in Oracle products.
During Q3 2023 Oracle Critical Patch Update, the Oracle Financial Services Applications received the highest number of 147 patches, constituting 29% of the total patches released. Oracle Communications and Oracle Fusion Middleware followe
http://packetstormsecurity.com/files/176334/Apache-2.4.55-mod_proxy-HTTP-Request-Smuggling.htmlhttps://httpd.apache.org/security/vulnerabilities_24.htmlhttps://lists.debian.org/debian-lts-announce/2023/04/msg00028.htmlhttps://security.gentoo.org/glsa/202309-01http://packetstormsecurity.com/files/176334/Apache-2.4.55-mod_proxy-HTTP-Request-Smuggling.htmlhttps://httpd.apache.org/security/vulnerabilities_24.htmlhttps://lists.debian.org/debian-lts-announce/2023/04/msg00028.htmlhttps://security.gentoo.org/glsa/202309-01
2023-03-07
Published
Exploited in the wild