Patch Released for RCE Vulnerability in pfSense Firewall - SOCRadar (2024)

A critical vulnerability has been discovered in a plugin ofNetgate’s pfSense firewall. The flaw is tracked asCVE-2022-31814and can expose the affected instances to unauthenticated remote code execution attacks.

pfSense is an open-source firewall and router software distribution based on FreeBSD. The firewall does not include the plugin named pfBlockerNG by default. pfBlockerNG enables allow-listing in the pfSense firewall, allowing the users to block specific IPs and entire countries.

To become exposed, the issue requires access to the web server on the firewall, which should never be open on WAN and is often restricted when configured per best practices.

The vulnerability affects pfBlockerNG versions 2.1.4_26 and earlier, and software updates are available to address the problem.

Patch Released for RCE Vulnerability in pfSense Firewall - SOCRadar (1)

Over 30K pfSense Machines Exposed

The CVSS score of the vulnerability is 9.8, as noted in IHTeam’s advisory since the web server is run by root and exploitable by unauthenticated attackers.

According to Netgate, the overall practical impact was deemed lower even though the issue received a high score. A Shodan search shows over 30,000 pfSense machines are exposed on the internet. And as Netgate also implies, this does not indicate the specific count of instances impacted by the plugin’s vulnerability.

Patch Released for RCE Vulnerability in pfSense Firewall - SOCRadar (2)

The pfSense firewall’s distributor, Netgate, stated that the issue uncovered by the researchers was in the pfBlockerNG package but had previously been addressed in the pfBlockerNG-devel package, the version the package maintainer recommends everyone use.

Developers continue shipping and enabling users to install between the 2.x and the 3.x branch. The researchers said, if the affected 2.x branch was removed entirely from the list of accessible plugins, the misunderstanding could be resolved quickly.

Proof-of-concept isAvailable

Software updates are available from pfSense, and the plugin’s developer, pfBlockerNG-devel, is a secure version recommended.

According to an IHTeam researcher, other software developers could learn from the flaw’s characteristics.

The researcher explained: “To avoid these types of vulnerabilities, developers should take extra care while handling user input (not only via direct GET and POST requests but also via input that might be passed in request headers such as Cookies, Host, or User-Agent). All user input should be carefully analyzed and sanitized before being passed to the application. This is also valid for other attacks such as cross-site scripting (XSS) or SQL injection, not only for command execution.”

The exploit code can be foundhere.

Check IHTeam’sblog postfor a technical description and proof-of-concept of the problem.

Patch Released for RCE Vulnerability in pfSense Firewall - SOCRadar (3)
Patch Released for RCE Vulnerability in pfSense Firewall - SOCRadar (2024)

FAQs

What is the new pfSense vulnerability? ›

pfSense v2. 5.2 was discovered to contain a cross-site scripting (XSS) vulnerability in the browser. php component. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into a file name.

What are the vulnerabilities in pfSense 2.7 0? ›

pfSense CE 2.7. 0 and below, pfSense Plus 23.05. 1 and below are vulnerable to two XSS vulnerabilities and a Command Injection vulnerability (CVE-2023-42325, CVE-2023-42327, CVE-2023-42326). The security vulnerabilities are fixed in pfSense CE 2.7.

What is the RCE vulnerability in FortiOS? ›

The ASD's ACSC is aware of an Unauthenticated Remote Code Execution (RCE) vulnerability (CVE-2024-21762) in Fortinet FortiOS devices. CVE-2024-21762 refers to an out-of-bounds write vulnerability that may allow Unauthenticated RCE via a specially crafted HTTP request.

What are the disadvantages of pfSense firewall? ›

Challenging web GUI setup and management: Non-expert users may find it challenging to set up and manage the web GUI, particularly when it comes to assigning WAN and LAN interfaces. Limited API and scripting capabilities: Some reviewers have highlighted the lack of an API for making changes in pfSense.

How secure is pfSense firewall? ›

Enhanced Security Monitoring: pfSense, being a powerful open-source firewall and router software, provides robust network security. However, adding Snort enhances security monitoring capabilities by providing an additional layer of defense against intrusions and malicious activities.

What are the 2 new high severity vulnerabilities that OpenSSL releases patch for? ›

The OpenSSL project released version 3.0. 7 on November 1, 2022, to address CVE-2022-3786 and CVE-2022-3602, two high-severity vulnerabilities affecting OpenSSL's 3.0. x version stream discovered and reported by Polar Bear and Viktor Dukhovni.

What is the latest version of pfSense? ›

pfSense
Released to manufacturingOct 2006
Latest releaseCommunity Edition: 2.7.2 (amd64) / December 7, 2023 Plus: 23.09.1 / December 7, 2023
Repositorygithub.com/pfsense/pfsense
Platforms32-bit (discontinued in 2.4.x); 64-bit Intel / AMD
Support status
11 more rows

Which is better, pfSense or OPNsense? ›

If you want high customizability and a large support community, pfSense is a good option. If you prioritize an easy-to-use interface and frequent updates, instead, OPNsense may be better. Ultimately, pfSense offers more flexibility for seasoned users, but OPNsense provides a more polished out-of-box experience.

What is RCE vulnerability? ›

How remote code execution (RCE) attacks work. Remote code execution attacks generally occur via vulnerabilities in web applications and network infrastructure. Remote code execution vulnerabilities are flaws in software that allow an attacker to run malicious code on a target system.

How bad is RCE? ›

RCE vulnerabilities are highly sought after by malicious actors. Exploiting these vulnerabilities can lead to devastating consequences, including data breaches, system compromises, and the propagation of malware or ransomware.

Can you get RCE from XSS? ›

In this article our security experts Tom and Almas explain how they managed to bypass client and server-side defenses in FortiADC, and turn an allegedly harmless XSS into RCE by optimally utilizing an extremely restricted payload space.

What is a new 0day vulnerability? ›

A zero-day vulnerability is unknown to the vendor, and thus there is no patch, mitigation, or fix available to address it. The term “zero-day” refers to the amount of time vendors have to address the flaw before hackers can exploit it.

What is the new Linux kernel vulnerability? ›

CISA has added a new security flaw affecting the Linux kernel to its Known Exploited Vulnerabilities (KEV) catalog. The vulnerability, CVE-2024-1086, allows attackers to elevate their privileges, even allowing the execution of random code.

What is new remote code execution vulnerability? ›

Remote access: RCE vulnerabilities are commonly used to give an attacker an initial foothold on a corporate network that they could then expand. For example, an RCE vulnerability could allow an attacker to steal login credentials that would allow them network access via a VPN.

What's the latest version of pfSense? ›

pfSense
Released to manufacturingOct 2006
Latest releaseCommunity Edition: 2.7.2 (amd64) / December 7, 2023 Plus: 23.09.1 / December 7, 2023
Repositorygithub.com/pfsense/pfsense
Platforms32-bit (discontinued in 2.4.x); 64-bit Intel / AMD
Support status
11 more rows

Top Articles
Time to check your policy? Car insurance rates up in 2024
Akshat Shrivastava on LinkedIn: If your income is 1 Crore, you will roughly pay 40%+ tax in India. (Plus… | 755 comments
Drury Inn & Suites Bowling Green
Forozdz
Www.1Tamilmv.cafe
Devon Lannigan Obituary
Mountain Dew Bennington Pontoon
Greedfall Console Commands
Identifont Upload
Okatee River Farms
Music Archives | Hotel Grand Bach - Hotel GrandBach
LeBron James comes out on fire, scores first 16 points for Cavaliers in Game 2 vs. Pacers
Craigslist Dog Kennels For Sale
Walmart Windshield Wiper Blades
Houses and Apartments For Rent in Maastricht
Las 12 mejores subastas de carros en Los Ángeles, California - Gossip Vehiculos
Lehmann's Power Equipment
Missouri Highway Patrol Crash
Accuweather Mold Count
Heart and Vascular Clinic in Monticello - North Memorial Health
Puss In Boots: The Last Wish Showtimes Near Cinépolis Vista
O'Reilly Auto Parts - Mathis, TX - Nextdoor
Receptionist Position Near Me
Sensual Massage Grand Rapids
Table To Formula Calculator
Ullu Coupon Code
Jamielizzz Leaked
Dairy Queen Lobby Hours
Desales Field Hockey Schedule
417-990-0201
Word Trip Level 359
Panchang 2022 Usa
Minecraft Jar Google Drive
Sedano's Supermarkets Expands to Orlando - Sedano's Supermarkets
Car Crash On 5 Freeway Today
Covalen hiring Ai Annotator - Dutch , Finnish, Japanese , Polish , Swedish in Dublin, County Dublin, Ireland | LinkedIn
Hermann Memorial Urgent Care Near Me
Ljw Obits
Eleceed Mangaowl
SOC 100 ONL Syllabus
Boggle BrainBusters: Find 7 States | BOOMER Magazine
Pinellas Fire Active Calls
Rs3 Bis Perks
Letter of Credit: What It Is, Examples, and How One Is Used
Karen Wilson Facebook
Candise Yang Acupuncture
Phmc.myloancare.com
La Qua Brothers Funeral Home
Erica Mena Net Worth Forbes
Zom 100 Mbti
Die 10 wichtigsten Sehenswürdigkeiten in NYC, die Sie kennen sollten
Selly Medaline
Latest Posts
Article information

Author: Laurine Ryan

Last Updated:

Views: 6374

Rating: 4.7 / 5 (77 voted)

Reviews: 84% of readers found this page helpful

Author information

Name: Laurine Ryan

Birthday: 1994-12-23

Address: Suite 751 871 Lissette Throughway, West Kittie, NH 41603

Phone: +2366831109631

Job: Sales Producer

Hobby: Creative writing, Motor sports, Do it yourself, Skateboarding, Coffee roasting, Calligraphy, Stand-up comedy

Introduction: My name is Laurine Ryan, I am a adorable, fair, graceful, spotless, gorgeous, homely, cooperative person who loves writing and wants to share my knowledge and understanding with you.