QID 34081

Date Published: 2023-12-14

QID 34081: pfSense Multiple Vulnerabilities (pfSense-SA-23_08, pfSense-SA-23_09, pfSense-SA-23_10, pfSense-SA-23_11)

pfSense is an open-source firewall/router which based on FreeBSD. pfsense can be deployed as a perimeter firewall, router, wireless access point, DHCP server, DNS server and VPN endpoint.

CVE-2023-42325:Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges.
CVE-2023-42326: An issue in Netgate pfSense v.2.7.0 allows a remote attacker to execute arbitrary code CVE-2023-42327:Cross Site Scripting (XSS) vulnerability in Netgate pfSense v.2.7.0 allows a remote attacker to gain privileges via a crafted URL to the getserviceproviders.php page.
Affected versions:
pfSense CE 2.7.0 and prior versions

QID detection logic (unauthenticated):
The QID checks for vulnerable versions of pfSense the version for pfSense is retrieved via SNMP.

Successful exploitation could attacker to gain privileges

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as Critical - 9 severity.
  • Solution
    Customers are advised to install Pfsense 2.7.1 or later versions to remediate this vulnerabilities.

    CVEs related to QID 34081

    Software Advisories
    Advisory ID Software Component Link
    pfSense-SA-23_08 URL Logo docs.netgate.com/downloads/pfSense-SA-23_08.webgui.asc
    pfSense-SA-23_09 URL Logo docs.netgate.com/downloads/pfSense-SA-23_09.webgui.asc
    pfSense-SA-23_10 URL Logo docs.netgate.com/downloads/pfSense-SA-23_10.webgui.asc