NA

CVE-2023-39001

Published: 09/08/2023 Updated: 10/10/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

A command injection vulnerability in the component diag_backup.php of OPNsense Community Edition prior to 23.7 and Business Edition prior to 23.4.2 allows malicious users to execute arbitrary commands via a crafted backup configuration file.

Vulnerable Product Search on Vulmon Subscribe to Product

opnsense opnsense