Описание
In Netgate pfSense CE 2.8.0, the "WebCfg - Diagnostics: Command" privilege allows reading arbitrary files via diag_command.php dlPath directory traversal. NOTE: the Supplier's perspective is that this is intended behavior for this privilege level, and that system administrators are informed through both the product documentation and UI.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party Advisory
Уязвимые конфигурации
EPSS
5 Medium
CVSS3
6.5 Medium
CVSS3
Дефекты
Связанные уязвимости
In Netgate pfSense CE 2.8.0, the "WebCfg - Diagnostics: Command" privilege allows reading arbitrary files via diag_command.php dlPath directory traversal. NOTE: the Supplier's perspective is that this is intended behavior for this privilege level, and that system administrators are informed through both the product documentation and UI.
Уязвимость компонента diag_command.php программного межсетевого экрана Netgate pfSense, позволяющая нарушителю читать произвольные файлы
EPSS
5 Medium
CVSS3
6.5 Medium
CVSS3