CVE-2023-27253
Published on: Not Yet Published
Last Modified on: 03/17/2023 10:15:00 PM UTC
The following vulnerability was found:
A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attackers to execute arbitrary commands via manipulating the contents of an XML file supplied to the component config.xml.
- CVE-2023-27253 has been assigned by
[email protected] to track the vulnerability
CVE References
Description | Tags ⓘ | Link |
---|---|---|
Correct RRD backup/restore cmd file handling. Fixes #13935 · pfsense/[email protected] · GitHub | github.com text/html |
![]() |
Bug #13935: RRD restore process does not sanitize filenames from backup XML - pfSense - pfSense bugtracker | redmine.pfsense.org text/html |
![]() |
There are currently no QIDs associated with this CVE
There are no known software configurations (CPEs) currently associated with this CVE
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2023-27253 : A command injection vulnerability in the function restore_rrddata of Netgate pfSense v2.7.0 allo… twitter.com/i/web/status/1… | 2023-03-17 22:01:53 |
![]() |
Potentially Critical CVE Detected! CVE-2023-27253 A command injection vulnerability in the function restore_rrddata… twitter.com/i/web/status/1… | 2023-03-17 22:56:00 |
![]() |
CVE-2023-27253 | 2023-03-17 22:38:16 |