Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-7hr6-mvjp-x5qv

Опубликовано: 29 июн. 2025
Источник: github
Github: Не прошло ревью
CVSS3: 5

Описание

In Netgate pfSense CE 2.8.0, the "WebCfg - Diagnostics: Command" privilege allows reading arbitrary files via diag_command.php dlPath directory traversal. NOTE: the Supplier's perspective is that this is intended behavior for this privilege level, and that system administrators are informed through both the product documentation and UI.

In Netgate pfSense CE 2.8.0, the "WebCfg - Diagnostics: Command" privilege allows reading arbitrary files via diag_command.php dlPath directory traversal. NOTE: the Supplier's perspective is that this is intended behavior for this privilege level, and that system administrators are informed through both the product documentation and UI.

EPSS

Процентиль: 12%
0.00041
Низкий

5 Medium

CVSS3

Дефекты

CWE-36

Связанные уязвимости

CVSS3: 5
nvd
7 месяцев назад

In Netgate pfSense CE 2.8.0, the "WebCfg - Diagnostics: Command" privilege allows reading arbitrary files via diag_command.php dlPath directory traversal. NOTE: the Supplier's perspective is that this is intended behavior for this privilege level, and that system administrators are informed through both the product documentation and UI.

EPSS

Процентиль: 12%
0.00041
Низкий

5 Medium

CVSS3

Дефекты

CWE-36