CVE-2023-37582
published 2023-07-12CVE-2023-37582: The RocketMQ NameServer component still has a remote command execution vulnerability as the CVE-2023-33246 issue was not completely fixed in version 5.1.1…
PriorityP192critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
ITWEXPLOITVulnCheck KEVInitial access
Exploited in the wild
EPSS
90.43%
99.8th percentile
The RocketMQ NameServer component still has a remote command execution vulnerability as the CVE-2023-33246 issue was not completely fixed in version 5.1.1.
When NameServer address are leaked on the extranet and lack permission verification, an attacker can exploit this vulnerability by using the update configuration function on the NameServer component to execute commands as the system users that RocketMQ is running as.
It is recommended for users to upgrade their NameServer version to 5.1.2 or above for RocketMQ 5.x or 4.9.7 or above for RocketMQ 4.x to prevent these attacks.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apache | rocketmq | <= 4.9.6 | — |
| apache | rocketmq | 5.0.0 – 5.1.1 | — |
Detection & IOCsextracted from sources · hover to see the quote
bytes
000000a4000000617b22636f6465223a3331382c22666c6167223a302c226c616e6775616765223a224a415641222c226f7061717565223a302c2273657269616c697a655479706543757272656e74525043223a224a534f4e222c2276657273696f6e223a3430357d636f6e66696753746f7265506174683d2f746d702f70776e65640a70726f64756374456e764e616d653d746573742f706174685c6e746573745c6e74657374
snort
alert tcp any any -> $HOME_NET any (msg:"ET EXPLOIT Apache RocketMQ Nameserver Arbitrary File Write (CVE-2023-37582)"; flow:established,to_server; content:"|22|code|22 3a|318"; content:"configStorePath|3d|"; content:"productEnvName|3d|"; fast_pattern; reference:url,github.com/Malayke/CVE-2023-37582_EXPLOIT; reference:cve,2023-37582; classtype:misc-attack; sid:2065400; rev:1; metadata:affected_product Apache_RocketMQ, attack_target Networking_Equipment, created_at 2025_10_27, cve CVE_2023_37582, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, updated_at 2025_10_27; target:dest_ip;)
- →Detect exploit attempts by matching TCP traffic to port 9876 containing RocketMQ NameServer update-config payload: look for code 318 (0x13e), 'configStorePath=' and 'productEnvName=' in the same stream.
- →Monitor for RocketMQ NameServer processes (port 9876) exposed on the internet without authentication; ShadowServer tracks hundreds of daily scanning/exploitation IPs targeting this service. ↗
- →Watch for DreamBus botnet activity dropping XMRig Monero miners on RocketMQ servers — a known post-exploitation payload chain for this CVE. ↗
- ·CVE-2023-37582 is a bypass/incomplete fix of CVE-2023-33246; both CVEs share the same attack vector (NameServer update configuration function) and should be treated as the same detection surface. ↗
- ·The vulnerability is only exploitable when the NameServer address is exposed on the extranet without permission verification; internal-only deployments have a significantly reduced attack surface. ↗
- ·ShadowServer-observed activity may include benign researcher scanning in addition to actual exploitation attempts, so raw scan counts should not be treated as confirmed compromise. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
ghsa9.8CRITICAL
osv9.8CRITICAL
vulncheck9.8CRITICAL
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
RocketMQ NameServer component Code Injection vulnerability
ghsa·2023-07-12·CVSS 9.8
CVE-2023-37582 [CRITICAL] CWE-94 RocketMQ NameServer component Code Injection vulnerability
RocketMQ NameServer component Code Injection vulnerability
The RocketMQ NameServer component still has a remote command execution vulnerability as the CVE-2023-33246 issue was not completely fixed in version 5.1.1.
When NameServer address are leaked on the extranet and lack permission verification, an attacker can exploit this vulnerability by using the update configuration function on the NameServer component to execute commands as the system users that RocketMQ is running as.
It is recommended for users to upgrade their NameServer version to 5.1.2 or above for RocketMQ 5.x or 4.9.7 or above for RocketMQ 4.x to prevent these attacks.
OSV
RocketMQ NameServer component Code Injection vulnerability
osv·2023-07-12·CVSS 9.8
CVE-2023-37582 [CRITICAL] RocketMQ NameServer component Code Injection vulnerability
RocketMQ NameServer component Code Injection vulnerability
The RocketMQ NameServer component still has a remote command execution vulnerability as the CVE-2023-33246 issue was not completely fixed in version 5.1.1.
When NameServer address are leaked on the extranet and lack permission verification, an attacker can exploit this vulnerability by using the update configuration function on the NameServer component to execute commands as the system users that RocketMQ is running as.
It is recommended for users to upgrade their NameServer version to 5.1.2 or above for RocketMQ 5.x or 4.9.7 or above for RocketMQ 4.x to prevent these attacks.
VulnCheck
Apache rocketmq Improper Control of Generation of Code ('Code Injection')
vulncheck·2023·CVSS 9.8
CVE-2023-37582 [CRITICAL] Apache rocketmq Improper Control of Generation of Code ('Code Injection')
Apache rocketmq Improper Control of Generation of Code ('Code Injection')
The RocketMQ NameServer component still has a remote command execution vulnerability as the CVE-2023-33246 issue was not completely fixed in version 5.1.1.
When NameServer address are leaked on the extranet and lack permission verification, an attacker can exploit this vulnerability by using the update configuration function on the NameServer component to execute commands as the system users that RocketMQ is running as.
It is recommended for users to upgrade their NameServer version to 5.1.2 or above for RocketMQ 5.x or 4.9.7 or above for RocketMQ 4.x to prevent these attacks.
Affected: Apache rocketmq
Required Action: Apply remediations or mitigations per vendor instructions or discontinue use of the product if
Suricata
ET EXPLOIT Apache RocketMQ Nameserver Arbitrary File Write (CVE-2023-37582)
suricata·2025-10-27·CVSS 9.8
CVE-2023-37582 [CRITICAL] ET EXPLOIT Apache RocketMQ Nameserver Arbitrary File Write (CVE-2023-37582)
ET EXPLOIT Apache RocketMQ Nameserver Arbitrary File Write (CVE-2023-37582)
Rule: alert tcp any any -> $HOME_NET any (msg:"ET EXPLOIT Apache RocketMQ Nameserver Arbitrary File Write (CVE-2023-37582)"; flow:established,to_server; content:"|22|code|22 3a|318"; content:"configStorePath|3d|"; content:"productEnvName|3d|"; fast_pattern; reference:url,github.com/Malayke/CVE-2023-37582_EXPLOIT; reference:cve,2023-37582; classtype:misc-attack; sid:2065400; rev:1; metadata:affected_product Apache_RocketMQ, attack_target Networking_Equipment, created_at 2025_10_27, cve CVE_2023_37582, deployment Perimeter, deployment Internal, confidence High, signature_severity Major, updated_at 2025_10_27; target:dest_ip;)
Nuclei
Apache RocketMQ - Remote Command Execution
nuclei·CVSS 9.8
CVE-2023-37582 [CRITICAL] Apache RocketMQ - Remote Command Execution
Apache RocketMQ - Remote Command Execution
The RocketMQ NameServer component still has a remote command execution vulnerability as the CVE-2023-33246 issue was not completely fixed in version 5.1.1. When NameServer address are leaked on the extranet and lack permission verification, an attacker can exploit this vulnerability by using the update configuration function on the NameServer component to execute commands as the system users that RocketMQ is running as. It is recommended for users to upgrade their NameServer version to 5.1.2 or above for RocketMQ 5.x or 4.9.7 or above for RocketMQ 4.x to prevent these attacks.
Template:
id: CVE-2023-37582
info:
name: Apache RocketMQ - Remote Command Execution
author: daffainfo
severity: critical
description: |
The RocketMQ NameServer component
Wiz
Crying Out Cloud - February Newsletter | Wiz
blogs_wiz·2024-02-01·CVSS 9.8
CVE-2023-33246 [CRITICAL] Crying Out Cloud - February Newsletter | Wiz
This month we’ve seen a lot of action, with both vulnerabilities and security incidents that have left users affected. We bring you the latest cloud security highlights, to help you stay informed and stay secure. Let's dive in.
Here are our top picks!
## 🐞 High Profile Vulnerabilities
Apache RocketMQ RCE vulnerability exploited in-the-wild
In August 2023 researchers identified attackers exploiting CVE-2023-33246, a critical vulnerability in Apache RocketMQ, to install the DreamBus bot, a malware strain last reported about publicly in 2021. On January 5, 2024 Apache stated that the patch for CVE-2023-33246 was in fact insufficient, and an additional CVE was assigned to the bypass - CVE-2023-37582. The latter vulnerability is also being exploited in the wild, so it is recommended to patc
Bleepingcomputer
Hackers target Apache RocketMQ servers vulnerable to RCE attacks
blogs_bleepingcomputer·2024-01-05·CVSS 9.8
CVE-2023-33246 [CRITICAL] Hackers target Apache RocketMQ servers vulnerable to RCE attacks
## Hackers target Apache RocketMQ servers vulnerable to RCE attacks
## Bill Toulas
Security researchers are detecting hundreds of IP addresses on a daily basis that scan or attempt to exploit Apache RocketMQ services vulnerable to a remote command execution flaw identified as CVE-2023-33246 and CVE-2023-37582.
Both vulnerabilities have a critical severity score and refer to an issue that remained active after the vendor's initial patch in May 2023.
Initially, the security issue was tracked as CVE-2023-33246 and impacted multiple components, including NameServer, Broker, and Controller.
Apache released a fix that was incomplete for the NameServer component in RocketMQ and continued to affect versions 5.1 and older of the distributed messaging and streaming platform.
"The RocketMQ Name
Greynoiseio
NoiseLetter October 2024
blogs_greynoiseio
NoiseLetter October 2024
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
2023-07-12
Published
Exploited in the wild