CVE-2014-4690: Path Traversal
Multiple directory traversal vulnerabilities in pfSense before 2.1.4 allow (1) remote attackers to read arbitrary .info files via a crafted path in the pkg parameter to pkgmgrinstall.php and allow (2) remote authenticated users to read arbitrary files via the downloadbackup parameter to systemfirmwarerestorefullbackup.php.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4690?
CVE-2014-4690 is considered a medium-severity vulnerability due to its potential to allow unauthorized file access.
How do I fix CVE-2014-4690?
To fix CVE-2014-4690, upgrade pfSense to version 2.1.4 or later.
What types of attacks are possible with CVE-2014-4690?
CVE-2014-4690 allows remote attackers to exploit directory traversal vulnerabilities to read arbitrary files.
Who is affected by CVE-2014-4690?
CVE-2014-4690 affects pfSense versions prior to 2.1.4.
What are the consequences of not addressing CVE-2014-4690?
Not addressing CVE-2014-4690 may lead to unauthorized access to sensitive information on the pfSense system.