ISOMAN

CVE

CVE-2023-27253

A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attackers to execute arbitrary commands via manipulating the contents of an XML file supplied to the component config.xml.

Severity
HIGH
CVSS
8.8
Published
Modified

Linked Releases

References

  1. http://packetstormsecurity.com/files/173487/pfSense-Restore-RRD-Data-Command-Injection.html
  2. https://github.com/pfsense/pfsense/commit/ca80d18493f8f91b21933ebd6b714215ae1e5e94
  3. https://redmine.pfsense.org/issues/13935
  4. http://packetstormsecurity.com/files/173487/pfSense-Restore-RRD-Data-Command-Injection.html
  5. https://github.com/pfsense/pfsense/commit/ca80d18493f8f91b21933ebd6b714215ae1e5e94
  6. https://redmine.pfsense.org/issues/13935