vendor:
pfSense CE
by:
FabDotNET (Fabien MAISONNETTE)
9.8
CVSS
CRITICAL
Authentication Bypass
287
CWE
Product Name: pfSense CE
Affected Version From: pfSenseCE <= 2.6.0
Affected Version To: pfSenseCE <= 2.6.0
Patch Exists: YES
Related CWE: CVE-2023-27100
CPE: a:netgate:pfsense_ce:2.6.0
Platforms Tested:
2023
pfsenseCE v2.6.0 – Anti-brute force protection bypass
This exploit allows an attacker to bypass the anti-brute force protection of pfsenseCE v2.6.0 by using a specially crafted POST request. The exploit is possible due to a lack of proper input validation and authentication checks.
Mitigation:
Upgrade to the latest version of pfsenseCE, which includes a patch for this vulnerability.