CVE-2023-38545Patch(fedoraproject / active_iq_unified_manager)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch fedoraproject active_iq_unified_manager systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

This flaw makes curl overflow a heap based buffer in the SOCKS5 proxy handshake. When curl is asked to pass along the host name to the SOCKS5 proxy to allow that to resolve the address instead of it getting done by curl itself, the maximum length that host name can be is 255 bytes. If the host name is detected to be longer, curl switches to local name resolving and instead passes on the resolved address only. Due to this bug, the local variable that means "let the host resolve the name" could get the wrong value during a slow SOCKS5 handshake, and contrary to the intention, copy the too long host name to the target buffer instead of copying just the resolved address there. The target buffer being a heap based buffer, and the host name coming from the URL that curl has been told to operate with.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-787

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • active_iq_unified_manager
  • fedora
  • libcurl
  • oncommand_insight

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • General: 2 classified signals
  • Peaked 3d ago at 1 mentions (2026-02-12); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Products
active_iq_unified_managerfedoralibcurloncommand_insightoncommand_workflow_automationwindows_10_1809windows_10_21h2windows_10_22h2windows_11_21h2windows_11_22h2

2 versions affected across 13 products

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-02-12: 1Mentions · 2026-03-10: 1Mentions · 2026-06-05: 1Mentions · 2026-06-25: 1Patch / Workaround · 2026-02-12: 1Patch / Workaround · 2026-03-10: 1Technical Details · 2026-02-12: 1Technical Details · 2026-03-10: 1Technical Details · 2026-06-05: 102-1203-1006-0506-25
Signal classification2 categories
Patch
250.0%
General
250.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-121
Patch1
2026-03-101
Patch1
2026-06-051
General1
2026-06-251
General1
Full discourse4 posts
  • nksistemas@nksistemas
    General

    CVE-2023-38545: La Vulnerabilidad Silenciosa de 25 Años en cURL y Su Impacto Crítico https://nksistemas.com/cve-2023-38545-la-vulnerabilidad-silenciosa-de-25-anos-en-curl-y-su-impacto-critico/

    Post summary

    The brief excerpt references CVE‑2023‑38545 but provides none of the detailed information needed to classify it under a more specific category.

    01010197
    6.2K followersView on X
  • Autumn Good@autumn_good_35
    Patch

    CVE-2023-38545 9.8 Critical CVE-2025-23048 9.1 Critical CVE-2025-55754 9.6 Critical HP Device Manager Vulnerability Update (5.0.16) | HP® Support https://support.hp.com/us-en/document/ish_14442335-14442364-16/hpsbhf04092

    Post summary

    The post references three critical CVEs and directs readers to an HP support update for the HP Device Manager, indicating a vendor patch has been released.

    01010496
    6.7K followersView on X
  • Mohi@disismohi
    General

    The dataset: CVE-2021-3156 (sudo heap overflow), CVE-2022-0847 (Dirty Pipe), CVE-2023-38545 (curl SOCKS5). Real vulnerable functions from OpenSSL, Linux kernel, cURL.

    Post summary

    The text briefly lists three CVEs with their vulnerability types and affected components, but it lacks details on exploits, patches, or active usage.

    1000047
    63 followersView on X
  • ThreatSynop@ThreatSynop
    Patch

    🚨 CISA flags critical curl heap overflow impacting Siemens Desigo CC & SENTRON Powermanager CISA’s ICSA-26-043-04 (Feb 12, 2026) warns that Siemens Desigo CC (V6–V8 < QU2) and SENTRON Powermanager (V6–V8 < QU2) inherit CVE-2023-38545—a network-reachable curl SOCKS5 heap-based buffer overflow that can enable code execution when exploited under specific handshake conditions—so orgs should update to fixed Siemens releases and/or upgrade the bundled third-party runtime per vendor guidance. 🎯 Target: Global/Building Management & Energy Monitoring (Facilities/Critical Manufacturing) #️⃣ Category: #Vulnerability #BlueTeam 🔗 URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-043-04

    Post summary

    CISA issues an advisory for CVE‑2023‑38545, a network‑reachable curl heap overflow affecting Siemens Desigo CC and SENTRON Powermanager, and urges organizations to apply vendor patches or upgrade the bundled runtime.

    00000137
    191 followersView on X
CPE platform detail14 entries

14 of 14 entries

PartVendorProductVersionTarget SWTarget HW
OSfedoraprojectfedora37--
Apphaxxlibcurl---
OSmicrosoftwindows_10_1809---
OSmicrosoftwindows_10_21h2---
OSmicrosoftwindows_10_22h2---
OSmicrosoftwindows_11_21h2---
OSmicrosoftwindows_11_22h2---
OSmicrosoftwindows_11_23h2---
OSmicrosoftwindows_server_2019---
OSmicrosoftwindows_server_2022---
Appnetappactive_iq_unified_manager-vmware_vsphere-
Appnetappactive_iq_unified_manager-windows-
Appnetapponcommand_insight---
Appnetapponcommand_workflow_automation---

Explore more