CVE-2014-4691: Medium severity netgate pfsense community edition vulnerability
Published Jul 2, 2014
·Updated
Session fixation vulnerability in pfSense before 2.1.4 allows remote attackers to hijack web sessions via a firewall login cookie.
Affected Software
1 affected component
Netgate pfSense<=2.1.3
Event History
Jul 2, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2014-4691?
CVE-2014-4691 is considered a high severity vulnerability due to its potential for session hijacking.
2
How do I fix CVE-2014-4691?
To fix CVE-2014-4691, upgrade pfSense to version 2.1.4 or later.
3
What impact does CVE-2014-4691 have on pfSense users?
CVE-2014-4691 allows remote attackers to hijack user sessions, compromising sensitive information.
4
Which versions of pfSense are affected by CVE-2014-4691?
pfSense versions prior to 2.1.4, including 2.1.3 and earlier, are affected by CVE-2014-4691.
5
Who is at risk from CVE-2014-4691?
Any pfSense user with versions 2.1.3 or earlier is at risk from session fixation attacks due to CVE-2014-4691.