📦

pfsense

Vendor: netgate

Actively Exploited 0 CISA KEV List
PoC / Exploits 9 Code Available
Total RCEs 11 Remote Access
Total CVEs 85 Total Indexed
Avg. EPSS 19.38% Exploit Prob.
Latest CVE CVE-2024-46538 Oct 22

Security Vulnerability Index

Page 1 / 9
4.8 CVSS

A cross-site scripting (XSS) vulnerability in pfsense v2.5.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the $pconfig variable at interfaces_groups_edit.php.

EPSS: 83.65%
8.8 CVSS
CVE-2023-48123
RCE Exploit Found

An issue in Netgate pfSense Plus v.23.05.1 and before and pfSense CE v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the packet_capture.php file.

EPSS: 68.24%
8.8 CVSS
CVE-2023-42326
RCE Exploit Found

An issue in Netgate pfSense v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the interfaces_gif_edit.php and interfaces_gre_edit.php components.

EPSS: 84.80%
5.4 CVSS

Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted URL to the getserviceproviders.php page.

EPSS: 48.31%
5.4 CVSS

Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted url to the status_logs_filter_dynamic.php page.

EPSS: 48.31%
9.6 CVSS

Cross Site Scripting vulnerability found in Netgate pfSense 2.4.4 and ACME package v.0.6.3 allows attackers to execute arbitrary code via the RootFolder field of acme_certificates.php.

EPSS: 1.88%
8.8 CVSS
CVE-2023-27253
RCE Exploit Found

A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attackers to execute arbitrary commands via manipulating the contents of an XML file supplied to the component config.xml.

EPSS: 79.15%
6.1 CVSS

pfSense CE through 2.6.0 and pfSense Plus before 22.05 allow XSS in the WebGUI via URL Table Alias URL parameters.

EPSS: 9.44%
6.1 CVSS

Cross Site Scripting (XSS) vulnerability in Netgate pf Sense 2.4.4-Release-p3 and Netgate ACME package 0.6.3 allows remote attackers to to run arbitrary code via the RootFolder field to acme_certificate_edit.php page of the ACME package.

EPSS: 0.62%
8.8 CVSS

Improper access control vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software versions prior to 22.01) allows a remote attacker with the privilege to change NTP GPS settings to rewrite existing files on the file system, which may result in arbitrary command execution.

EPSS: 1.11%