Netgate Pfsense Plus vulnerabilities

10 known vulnerabilities affecting netgate/pfsense_plus.

Total CVEs
10
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH5MEDIUM4

Vulnerabilities

Page 1 of 1
CVE-2024-54780HIGHCVSS 8.8fixed in 25.032025-05-14
CVE-2024-54780 [HIGH] CWE-94 CVE-2024-54780: Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds are vulnerable to com Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds are vulnerable to command injection in the OpenVPN widget due to improper sanitization of user-supplied input to the OpenVPN management interface. An authenticated attacker can exploit this vulnerability by injecting arbitrary OpenVPN management commands via the remipp param
nvd
CVE-2024-54779MEDIUMCVSS 5.4fixed in 25.032025-05-14
CVE-2024-54779 [MEDIUM] CWE-79 CVE-2024-54779: Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cros Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross Site Scripting (XSS) in widgets/log.widget.php.
nvd
CVE-2024-57273MEDIUMCVSS 5.4fixed in 25.032025-05-14
CVE-2024-57273 [MEDIUM] CWE-79 CVE-2024-57273: Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cros Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross-site scripting (XSS) in the Automatic Configuration Backup (ACB) service, allowing remote attackers to execute arbitrary JavaScript, delete backups, or leak sensitive information via an unsanitized "reason" field and a derivable device key generated
nvd
CVE-2023-48795MEDIUMCVSS 5.9PoC≤ 23.09.12023-12-18
CVE-2023-48795 [MEDIUM] CWE-354 CVE-2023-48795: The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other pr The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some security features have been downgr
nvd
CVE-2023-48123HIGHCVSS 8.8≤ 23.05.12023-12-06
CVE-2023-48123 [HIGH] CVE-2023-48123: An issue in Netgate pfSense Plus v.23.05.1 and before and pfSense CE v.2.7.0 allows a remote attacke An issue in Netgate pfSense Plus v.23.05.1 and before and pfSense CE v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the packet_capture.php file.
nvd
CVE-2023-42326HIGHCVSS 8.8≤ 23.05.12023-11-14
CVE-2023-42326 [HIGH] CWE-77 CVE-2023-42326: An issue in Netgate pfSense v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted An issue in Netgate pfSense v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the interfaces_gif_edit.php and interfaces_gre_edit.php components.
nvd
CVE-2023-27100CRITICALCVSS 9.8PoCv22.05.12023-03-22
CVE-2023-27100 [CRITICAL] CWE-307 CVE-2023-27100: Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSen Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE software v2.6.0 allows attackers to bypass brute force protection mechanisms via crafted web requests.
nvd
CVE-2022-26019HIGHCVSS 8.8fixed in 22.012022-03-31
CVE-2022-26019 [HIGH] CWE-22 CVE-2022-26019: Improper access control vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions p Improper access control vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software versions prior to 22.01) allows a remote attacker with the privilege to change NTP GPS settings to rewrite existing files on the file system, which may result in arbitrary command execution.
nvd
CVE-2022-24299HIGHCVSS 8.8fixed in 22.012022-03-31
CVE-2022-24299 [HIGH] CWE-20 CVE-2022-24299: Improper input validation vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions Improper input validation vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software versions prior to 22.01) allows a remote attacker with the privilege to change OpenVPN client or server settings to execute an arbitrary command.
nvd
CVE-2021-20729MEDIUMCVSS 6.1≤ 21.052022-03-31
CVE-2021-20729 [MEDIUM] CWE-79 CVE-2021-20729: Cross-site scripting vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions 2.5. Cross-site scripting vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions 2.5.2 and earlier, and pfSense Plus software versions 21.05 and earlier) allows a remote attacker to inject an arbitrary script via a malicious URL.
nvd
Netgate Pfsense Plus vulnerabilities | cvebase