Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2023-54386

CVE-2023-54386: Rejected CVE Entry Status Explanation

CVE-2023-54386 is a rejected CVE identifier that was erroneously reserved under the wrong year due to an automation defect and was never assigned. This article explains the rejection status and CVE reservation process.

Published:

CVE-2023-54386 Overview

CVE-2023-54386 is a rejected CVE entry. According to the National Vulnerability Database (NVD), this identifier was erroneously reserved under the wrong year due to an automation defect and was never assigned to an actual vulnerability. No affected products, vendors, or technical details exist for this identifier.

Security teams encountering references to CVE-2023-54386 in scanners, threat intelligence feeds, or vulnerability management tools should treat it as invalid. The entry carries no severity rating, no Common Weakness Enumeration (CWE) mapping, and no associated exploit activity.

Critical Impact

No impact. This CVE identifier was rejected by the CVE Numbering Authority (CNA) and does not represent a real vulnerability.

Affected Products

  • No affected products — identifier never assigned to a vulnerability
  • No vendor advisories issued
  • No software versions impacted

Discovery Timeline

  • 2026-08-06 - CVE-2023-54386 published to NVD as a rejected entry
  • 2026-08-06 - Last updated in NVD database

Technical Details for CVE-2023-54386

Vulnerability Analysis

CVE-2023-54386 contains no vulnerability data. The CVE Program rejected this identifier with the stated reason: "Erroneously reserved under wrong year by automation defect; never assigned." The identifier exists in the NVD catalog solely to document its rejected status and prevent confusion with reused numbering.

Rejected CVE entries occur when a CNA reserves an identifier that is later determined to be duplicative, invalid, or reserved in error. In this case, an automation defect assigned the identifier to the wrong calendar year block. The CVE Program preserves the entry as rejected rather than deleting it, maintaining referential integrity across security tooling.

Root Cause

The root cause is administrative rather than technical. An automation defect in the CVE reservation workflow allocated this identifier under an incorrect year. No software flaw, configuration weakness, or code defect is associated with CVE-2023-54386.

Attack Vector

Not applicable. No attack vector exists because no vulnerability was ever documented under this identifier. Any threat intelligence report, vulnerability scanner finding, or advisory referencing CVE-2023-54386 as an exploitable issue is inaccurate and should be validated against the authoritative NVD record.

Detection Methods for CVE-2023-54386

Indicators of Compromise

  • No indicators of compromise apply. CVE-2023-54386 is a rejected identifier with no associated malicious activity, exploit code, or attack telemetry.
  • Any IOC feed attributing activity to CVE-2023-54386 should be treated as a data-quality issue in the upstream source.

Detection Strategies

  • Filter rejected CVE entries from vulnerability management dashboards to reduce analyst noise and avoid triaging non-issues.
  • Cross-reference CVE identifiers against the authoritative NVD database before opening remediation tickets to confirm the entry is active and not rejected.
  • Configure vulnerability scanners to suppress or flag rejected CVE identifiers so operations teams do not chase phantom findings.

Monitoring Recommendations

  • Audit threat intelligence platforms for enrichment records that reference rejected CVEs and correct or suppress those records at the source.
  • Track CVE status changes through the CVE Program to catch identifiers that transition between reserved, assigned, published, and rejected states.

How to Mitigate CVE-2023-54386

Immediate Actions Required

  • No patching action is required. CVE-2023-54386 does not describe a real vulnerability and cannot be exploited.
  • Update internal vulnerability tracking systems to mark CVE-2023-54386 as rejected and close any tickets opened against it.
  • Notify downstream consumers of your vulnerability data — such as governance, risk, and compliance (GRC) teams — that the identifier is invalid.

Patch Information

No patch exists or is needed. The CVE Program has classified this identifier as rejected, meaning it will never receive a vulnerability description, CVSS score, or vendor advisory. Consult the official NVD entry for CVE-2023-54386 for authoritative status.

Workarounds

  • Ignore any scanner alerts referencing CVE-2023-54386 after verifying the rejected status in NVD.
  • Report inaccurate references in commercial or open-source threat intelligence feeds to the vendor so the invalid entry can be purged.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.