CVE-2014-4688: Medium severity netgate pfsense community edition vulnerability
pfSense before 2.1.4 allows remote authenticated users to execute arbitrary commands via (1) the hostname value to diagdns.php in a Create Alias action, (2) the smartmonemail value to diagsmart.php, or (3) the database value to statusrrdgraphimg.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4688?
CVE-2014-4688 is considered a high severity vulnerability due to the potential for remote authenticated users to execute arbitrary commands.
How do I fix CVE-2014-4688?
To fix CVE-2014-4688, upgrade pfSense to version 2.1.4 or later.
Who is affected by CVE-2014-4688?
CVE-2014-4688 affects pfSense versions before 2.1.4.
What types of actions can be exploited in CVE-2014-4688?
CVE-2014-4688 can be exploited through the hostname value in diag_dns.php, the smartmonemail value in diag_smart.php, and the database value in status_rrd_graph_img.php.
Are there known exploits for CVE-2014-4688?
Yes, there are known exploits for CVE-2014-4688 that leverage the vulnerabilities in pfSense versions before 2.1.4.