QID 34079

Date Published: 2022-05-25

QID 34079: pfSense Multiple Vulnerabilities (PFSENSE-SA-22_04)

pfSense is an open-source firewall/router which based on FreeBSD. pfsense can be deployed as a perimeter firewall, router, wireless access point, DHCP server, DNS server and VPN endpoint.

A Cross-Site Scripting (XSS) vulnerability was found in pkg.php, a component of the pfSense Plus and pfSense CE software GUI. This problems is present on pfSense Plus version 21.05.2, pfSense CE version 2.5.2, and earlier versions of both.

Affected versions:
pfsense versions prior to 2.6.0

QID detection logic (unauthenticated):
The QID checks for vulnerable versions of pfSense the version for pfSense is retrieved via SNMP.

Due to the lack of proper encoding on the affected parameters susceptible to XSS, arbitrary JavaScript could be executed in the user's browser. The user's session cookie or other information from the session may be compromised.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as Critical - 9 severity.
  • Solution
    Customers are advised to install Pfsense 2.6.0 or later versions to remediate this vulnerabilities.

    CVEs related to QID 34079

    Software Advisories
    Advisory ID Software Component Link
    PFSENSE-SA-22_04 URL Logo docs.netgate.com/downloads/pfSense-SA-22_04.webgui.asc