pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metacharacters in the HTTP Host header. NOTE: 3.x is unaffected.
References
Link | Resource |
---|---|
https://www.ihteam.net/advisory/pfblockerng-unauth-rce-vulnerability/ | Exploit Technical Description Third Party Advisory |
https://docs.netgate.com/pfsense/en/latest/packages/pfblocker.html | Release Notes Vendor Advisory |
http://packetstormsecurity.com/files/168743/pfSense-pfBlockerNG-2.1.4_26-Shell-Upload.html | Exploit Third Party Advisory VDB Entry |
http://packetstormsecurity.com/files/171123/pfBlockerNG-2.1.4_26-Remote-Code-Execution.html |
Configurations
Information
Published : 2022-09-05 09:15
Updated : 2023-02-27 09:15
NVD link : CVE-2022-31814
Mitre link : CVE-2022-31814
JSON object : View
CWE
Products Affected
netgate
- pfblockerng