CVE漏洞中文网

0DayBank一个专门收集整理全球互联网漏洞的公开发布网站
  1. 首页
  2. CVE
  3. 正文

pfSense Command-injection vulnerabilities (pfSense-SA-16_05)

2017年8月29日 1141点热度 0人点赞 0条评论

漏洞类别:Firewall

漏洞等级:

漏洞信息

pfSense is an open-source firewall/router which based on FreeBSD. pfsense can be deployed as a perimeter firewall, router, wireless access point, DHCP server, DNS server and VPN endpoint.

The WebGUI in pfSense is affected with Command-injection vulnerabilities which allows non-admin users to gain increased privileges, read other files, execute commands, or perform other alterations.

Affected Versions:
pfSense prior to version 2.3.1_1

QID detection logic (unauthenticated):
The QID checks for vulnerable versions of pfSense (prior to 2.3.1_1), the version for pfSense is retrieved via SNMP.

漏洞危害

Successful exploitation of the vulnerabilities leads to privilege escalation.

解决方案

For more information, Customers are advised to refer the following advisory:
pfSense-SA-16_05.

Patch:
Following are links for downloading patches to fix the vulnerabilities:

pfSense-SA-16_05

0daybank

标签: 暂无
最后更新:2017年8月29日

小助手

这个人很懒,什么都没留下

点赞
< 上一篇
下一篇 >

文章评论

您需要 登录 之后才可以评论

COPYRIGHT © 2024 www.pdr.cn CVE漏洞中文网. ALL RIGHTS RESERVED.

鲁ICP备2022031030号

联系邮箱:wpbgssyubnmsxxxkkk@proton.me