CVE-2023-27253
high · 8.8A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attackers to execute arbitrary commands via manipulating the contents of an XML file supplied to the component config.xml.
8.8
CVSS
89.5%
EPSS (exploit prob.)
100th
EPSS percentile
2023-03-17
Published
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-91
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| netgate | pfsense | 2.7.0 |
Check a specific version with /api/v1/cve/match.
References
- http://packetstormsecurity.com/files/173487/pfSense-Restore-RRD-Data-Command-Injection.html
- https://github.com/pfsense/pfsense/commit/ca80d18493f8f91b21933ebd6b714215ae1e5e94
- https://redmine.pfsense.org/issues/13935
- http://packetstormsecurity.com/files/173487/pfSense-Restore-RRD-Data-Command-Injection.html
- https://github.com/pfsense/pfsense/commit/ca80d18493f8f91b21933ebd6b714215ae1e5e94
- https://redmine.pfsense.org/issues/13935
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2023-27253