Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-36p3-j543-mpj6

Опубликовано: 01 апр. 2022
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

Improper input validation vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software versions prior to 22.01) allows a remote attacker with the privilege to change OpenVPN client or server settings to execute an arbitrary command.

Improper input validation vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software versions prior to 22.01) allows a remote attacker with the privilege to change OpenVPN client or server settings to execute an arbitrary command.

EPSS

Процентиль: 50%
0.00269
Низкий

8.8 High

CVSS3

Дефекты

CWE-20

Связанные уязвимости

CVSS3: 8.8
nvd
почти 4 года назад

Improper input validation vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software versions prior to 22.01) allows a remote attacker with the privilege to change OpenVPN client or server settings to execute an arbitrary command.

EPSS

Процентиль: 50%
0.00269
Низкий

8.8 High

CVSS3

Дефекты

CWE-20