Unauthorized Password Change Vulnerability in Pfsense CE Software
CVE-2023-29975

7.2HIGH

Key Information:

Vendor

Pfsense

Status
Vendor
CVE Published:
9 November 2023

What is CVE-2023-29975?

An identified issue in Pfsense CE version 2.6.0 enables unauthenticated attackers to change the passwords of any user. This vulnerability poses a significant security risk, as it could lead to unauthorized access to sensitive data and systems. It is crucial for users of Pfsense CE to assess their security measures and update the software promptly to mitigate potential threats.

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.