Improper access control vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions before 2.6.0 and pfSense Plus software versions before 22.01) allows a remote attacker with the privilege to change NTP GPS settings to rewrite existing files on the file system, which may result in arbitrary command execution.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
netgate pfsense plus |
||
netgate pfsense |