1
23.7 Legacy Series / Re: Recent pfSense CVEs CVE-2023-42325, CVE-2023-42326, or CVE-2023-42327
« on: December 14, 2023, 11:37:00 pm »
Adding some links for anyone's convenience in looking things up:
For completeness:
- Sonar: pfSense Security: Sensing Code Vulnerabilities with SonarCloud (original writeup on the vulnerability found in pfSense)
- Mitre: CVE-2023-42327: Cross Site Scripting (XSS)
- NIST: CVE-2023-42327 Detail CVSS3 Score: 5.4
- Mitre: CVE-2023-42326: Remote code execution (RCE)
- NIST: CVE-2023-42326 Detail CVSS3 Sore: 8.8
- pfSense-SA-23_10.webgui:Authenticated Command Execution in the WebGUI
For completeness:
- Mitre: CVE-2023-42325 another Cross Site Scripting (XSS) issue
- NIST: CVE-2023-42325 Detail CVSS3 Score: 5.4