Логотип exploitDog
bind:CVE-2024-57273
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2024-57273

Количество 3

Количество 3

nvd логотип

CVE-2024-57273

9 месяцев назад

Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross-site scripting (XSS) in the Automatic Configuration Backup (ACB) service, allowing remote attackers to execute arbitrary JavaScript, delete backups, or leak sensitive information via an unsanitized "reason" field and a derivable device key generated from the public SSH key.

CVSS3: 5.4
EPSS: Низкий
github логотип

GHSA-v5vr-7qc6-xw56

9 месяцев назад

Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross-site scripting (XSS) in the Automatic Configuration Backup (ACB) service, allowing remote attackers to execute arbitrary JavaScript, delete backups, or leak sensitive information via an unsanitized "reason" field and a derivable device key generated from the public SSH key.

CVSS3: 5.4
EPSS: Низкий
fstec логотип

BDU:2026-00174

около 1 года назад

Уязвимость службы автоматического резервного копирования конфигурации программного межсетевого экрана на базе операционной системы FreeBSD Netgate pfSense, позволяющая нарушителю выполнить произвольный код

CVSS3: 5.4
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2024-57273

Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross-site scripting (XSS) in the Automatic Configuration Backup (ACB) service, allowing remote attackers to execute arbitrary JavaScript, delete backups, or leak sensitive information via an unsanitized "reason" field and a derivable device key generated from the public SSH key.

CVSS3: 5.4
0%
Низкий
9 месяцев назад
github логотип
GHSA-v5vr-7qc6-xw56

Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross-site scripting (XSS) in the Automatic Configuration Backup (ACB) service, allowing remote attackers to execute arbitrary JavaScript, delete backups, or leak sensitive information via an unsanitized "reason" field and a derivable device key generated from the public SSH key.

CVSS3: 5.4
0%
Низкий
9 месяцев назад
fstec логотип
BDU:2026-00174

Уязвимость службы автоматического резервного копирования конфигурации программного межсетевого экрана на базе операционной системы FreeBSD Netgate pfSense, позволяющая нарушителю выполнить произвольный код

CVSS3: 5.4
0%
Низкий
около 1 года назад

Уязвимостей на страницу