CVE-2023-27253

HIGH EPSS 99.8%
Published Mar 17, 20233y ago · Modified Jun 17, 20261w ago
8.8 CVSS 3.1
High
Find Similar
Published Mar 17, 2023 3y ago
Last Modified Jun 17, 2026 1w ago

Description

A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attackers to execute arbitrary commands via manipulating the contents of an XML file supplied to the component config.xml.

CVSS Details

Base Score
8.8
Exploitability
2.8
Impact
5.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector Network
Attack Complexity Low
Privileges Required Low
User Interaction None
Scope Unchanged
Confidentiality High
Integrity High
Availability High

Threat Intelligence

EPSS Exploit Probability
99.8% percentile
Exploit & Patch Status
No Known Exploit
Patch Available

Weaknesses 1

CWE-91

Affected Products 1

VendorProductVersionRange
netgatepfsense2.7.0any

References 3

  • packetstormsecurity.com http://packetstormsecurity.com/files/173487/pfSense-Restore-RRD-Data-Command-Injection.html
  • github.com https://github.com/pfsense/pfsense/commit/ca80d18493f8f91b21933ebd6b714215ae1e5e94
    Patch
  • redmine.pfsense.org https://redmine.pfsense.org/issues/13935
    Issue TrackingPatchVendor Advisory

Remediation

  • github.com https://github.com/pfsense/pfsense/commit/ca80d18493f8f91b21933ebd6b714215ae1e5e94
    Patch
  • redmine.pfsense.org https://redmine.pfsense.org/issues/13935
    Issue TrackingPatchVendor Advisory