Command Injection Vulnerability in Netgate pfSense CE 2.4.4-RELEASE
CVE-2018-4019

7.2HIGH

Key Information:

Vendor

Netgate

Vendor
CVE Published:
3 December 2018

What is CVE-2018-4019?

A command injection vulnerability affects the Netgate pfSense CE 2.4.4-RELEASE, specifically how it processes parameters from unauthorized POST requests. This flaw allows an attacker, with the correct credentials, to exploit the system by executing arbitrary commands, particularly through the powerd_normal_mode parameter. As a result, an attacker can gain unauthorized control of the system, posing significant security risks.

Affected Version(s)

Netgate pfSense Netgate pfSense CE 2.4.4-RELEASE

References

EPSS Score

85% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.