Brute-force Authentication Weakness in DECISO OPNsense Network Security Solution
CVE-2023-27152

9.8CRITICAL

Key Information:

Vendor

Opnsense

Status
Vendor
CVE Published:
23 October 2023

What is CVE-2023-27152?

The DECISO OPNsense version 23.1 is exposed to a vulnerability that lacks rate limiting for authentication attempts. This oversight enables attackers to execute brute-force attacks, potentially leading to unauthorized access by bypassing normal authentication procedures. Organizations using this version must take immediate measures to secure their authentication mechanisms against such attacks.

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.