vendor:
pfsense
by:
ghost_fh
8.8
CVSS
HIGH
Cross-Site Request Forgery
352
CWE
Product Name: pfsense
Affected Version From: 2.4.4-p3
Affected Version To: 2.4.4-p3
Patch Exists: YES
Related CWE: CVE-2019-16667
CPE: a:pfsense:pfsense
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: freebsd
2019
pfSense 2.4.4-p3 – Cross-Site Request Forgery
The pfsense firewall is vulnerable to RCE chained with CSRF as it uses `csrf magic` library since it allows to tamper the CSRF token values submitted when processing the form requests. An attacker can exploit this vulnerability by crafting a malicious page containing attacker's controlled input such as a 'reverse shell' and entice the victims to click on the crafted link via social engineering methods. Once the victim clicks on the link, the attacker can take the lateral control of the victim's machine and malicious actions can be performed on the victim's behalf.
Mitigation:
Ensure that the application is using a secure CSRF token and that the token is validated on the server side.