9.8
CVSSv3

CVE-2023-27100

Published: 22/03/2023 Updated: 10/04/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE software v2.6.0 allows malicious users to bypass brute force protection mechanisms via crafted web requests.

Vulnerable Product Search on Vulmon Subscribe to Product

netgate pfsense plus 22.05.1

pfsense pfsense 2.6.0

Exploits

pfsenseCE version 260 suffers from an anti-brute force protection bypass vulnerability ...

Github Repositories

[CVE-2023-27100 - pfSense Anti-brute force protection bypass] Problem Description The authentication system attempts to be informative and print extra information along with IP addresses to completely identify where a user logs in from when they login using the GUI This includes the authentication source (eg local database, LDAP or RADIUS, authentication server name), plus c