Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-fx6v-jrpq-f762

Опубликовано: 14 мая 2025
Источник: github
Github: Не прошло ревью
CVSS3: 8.8

Описание

Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds are vulnerable to command injection in the OpenVPN widget due to improper sanitization of user-supplied input to the OpenVPN management interface. An authenticated attacker can exploit this vulnerability by injecting arbitrary OpenVPN management commands via the remipp parameter.

Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds are vulnerable to command injection in the OpenVPN widget due to improper sanitization of user-supplied input to the OpenVPN management interface. An authenticated attacker can exploit this vulnerability by injecting arbitrary OpenVPN management commands via the remipp parameter.

EPSS

Процентиль: 76%
0.00932
Низкий

8.8 High

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 8.8
nvd
9 месяцев назад

Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds are vulnerable to command injection in the OpenVPN widget due to improper sanitization of user-supplied input to the OpenVPN management interface. An authenticated attacker can exploit this vulnerability by injecting arbitrary OpenVPN management commands via the remipp parameter.

CVSS3: 8.8
fstec
около 1 года назад

Уязвимость программного межсетевого экрана на базе операционной системы FreeBSD Netgate pfSense, связанная с неверным управлением генерацией кода, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 76%
0.00932
Низкий

8.8 High

CVSS3

Дефекты

CWE-94