Remote Code Execution Vulnerability in Netgate pfSense Products
CVE-2023-48123
Key Information:
- Vendor
Netgate
- Status
- Vendor
- CVE Published:
- 6 December 2023
Badges
What is CVE-2023-48123?
A vulnerability in Netgate pfSense Plus versions up to 23.05.1 and pfSense CE version 2.7.0 enables a remote attacker to execute arbitrary code by sending specially crafted requests to the packet_capture.php file. This flaw poses significant risks, allowing malicious users to manipulate the underlying system without authorization. Affected users should prioritize immediate updates to secure their installations against potential exploitation.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
EPSS Score
55% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability Reserved