Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7hr6-mvjp-x5qv

Опубликовано: 29 июн. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5

Описание

In Netgate pfSense CE 2.8.0, the "WebCfg - Diagnostics: Command" privilege allows reading arbitrary files via diag_command.php dlPath directory traversal. NOTE: the Supplier's perspective is that this is intended behavior for this privilege level, and that system administrators are informed through both the product documentation and UI.

In Netgate pfSense CE 2.8.0, the "WebCfg - Diagnostics: Command" privilege allows reading arbitrary files via diag_command.php dlPath directory traversal. NOTE: the Supplier's perspective is that this is intended behavior for this privilege level, and that system administrators are informed through both the product documentation and UI.

EPSS

Процентиль: 77%
0.01807
Низкий

5 Medium

CVSS3

Дефекты

CWE-36

Связанные уязвимости

CVSS3: 5
nvd
около 1 года назад

In Netgate pfSense CE 2.8.0, the "WebCfg - Diagnostics: Command" privilege allows reading arbitrary files via diag_command.php dlPath directory traversal. NOTE: the Supplier's perspective is that this is intended behavior for this privilege level, and that system administrators are informed through both the product documentation and UI.

CVSS3: 5
fstec
около 1 года назад

Уязвимость компонента diag_command.php программного межсетевого экрана Netgate pfSense, позволяющая нарушителю читать произвольные файлы

EPSS

Процентиль: 77%
0.01807
Низкий

5 Medium

CVSS3

Дефекты

CWE-36