CVE-2015-2295: CSRF
Cross-site request forgery (CSRF) vulnerability in systemfirmwarerestorefullbackup.php in the WebGUI in pfSense before 2.2.1 allows remote attackers to hijack the authentication of administrators for requests that delete arbitrary files via the deletefile parameter.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2015-2295?
CVE-2015-2295 is considered a medium-severity vulnerability due to its potential to compromise administrative authentication.
How do I fix CVE-2015-2295?
To fix CVE-2015-2295, upgrade pfSense to version 2.2.1 or later to mitigate the CSRF vulnerability.
Who is affected by CVE-2015-2295?
CVE-2015-2295 affects pfSense versions prior to 2.2.1, allowing remote attackers to exploit its WebGUI.
What type of attack does CVE-2015-2295 involve?
CVE-2015-2295 involves a Cross-Site Request Forgery (CSRF) attack that can lead to unauthorized file deletion.
Can CVE-2015-2295 be exploited remotely?
Yes, CVE-2015-2295 can be exploited remotely by attackers to hijack authentication of pfSense administrators.