9
CVSSv2

CVE-2019-16701

Published: 25/09/2019 Updated: 25/09/2019
CVSS v2 Base Score: 9 | Impact Score: 10 | Exploitability Score: 8
CVSS v3 Base Score: 8.8 | Impact Score: 5.9 | Exploitability Score: 2.8
VMScore: 905
Vector: AV:N/AC:L/Au:S/C:C/I:C/A:C

Vulnerability Summary

pfSense up to and including 2.3.4 up to and including 2.4.4-p3 allows Remote Code Injection via a methodCall XML document with a pfsense.exec_php call containing shell metacharacters in a parameter value.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

netgate pfsense 2.4.4

netgate pfsense

Exploits

# Exploit Title: Pfsense 234 / 244-p3 - Remote Code Injection # Date: 23/09/2018 # Author: Nassim Asrir # Vendor Homepage: wwwpfsenseorg/ # Contact: wassline@gmailcom | wwwlinkedincom/in/nassim-asrir-b73a57122/ # CVE: CVE-2019-16701 # Tested On: Windows 10(64bit) | Pfsense 234 / 244-p3 ################################## ...
pfSense versions 234 and 244-p3 remote code injection exploit ...