Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2025-34173

Опубликовано: 09 сент. 2025
Источник: nvd
CVSS3: 4.3
EPSS Низкий

Описание

In pfSense CE /usr/local/www/snort/snort_ip_reputation.php, the value of the iplist parameter is not sanitized of directory traversal-related characters/strings before being used to check if a file exists. While the contents of the file cannot be read, the server reveals whether a file exists, which allows an attacker to enumerate files on the target. The attacker must be authenticated with at least "WebCfg - Services: Snort package" permissions.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:pfsense:pfsense:*:*:*:*:community:*:*:*
Версия до 2.8.0 (исключая)

EPSS

Процентиль: 13%
0.00044
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-22

Связанные уязвимости

CVSS3: 4.3
github
5 месяцев назад

In pfSense CE /usr/local/www/snort/snort_ip_reputation.php, the value of the iplist parameter is not sanitized of directory traversal-related characters/strings before being used to check if a file exists. While the contents of the file cannot be read, the server reveals whether a file exists, which allows an attacker to enumerate files on the target. The attacker must be authenticated with at least "WebCfg - Services: Snort package" permissions.

EPSS

Процентиль: 13%
0.00044
Низкий

4.3 Medium

CVSS3

Дефекты

CWE-22