Directory Traversal Vulnerability in OPNsense Community and Business Editions
CVE-2023-38997

7.2HIGH

Key Information:

Vendor

Opnsense

Status
Vendor
CVE Published:
9 August 2023

What is CVE-2023-38997?

A directory traversal vulnerability has been identified in the Captive Portal templates of OPNsense products, specifically affecting the Community Edition versions prior to 23.7 and the Business Edition versions prior to 23.4.2. This flaw allows a malicious actor to exploit the system by crafting a specially-designed ZIP archive, which can lead to the execution of arbitrary commands with root privileges. The vulnerability poses significant risks as it can enable attackers to manipulate system files and execute unauthorized commands, compromising the overall security of affected systems.

References

CVSS V3.1

Score:
7.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.