CVE-2016-10709: OS Command Injection
Published Jan 22, 2018
·Updated
pfSense before 2.3 allows remote authenticated users to execute arbitrary OS commands via a '|' character in the statusrrdgraphimg.php graph parameter, related to rrdgraphimg.php.
Affected Software
1 affected component
pfSense pfSense<=2.2.6
Event History
Jan 22, 2018
CVE Published
via MITRE·04:00 AM
Data Sourced
via MITRE·04:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2016-10709?
The severity of CVE-2016-10709 is critical with a CVSS score of 8.8.
2
How does CVE-2016-10709 affect pfSense?
CVE-2016-10709 affects pfSense versions up to and including 2.2.6.
3
How can remote authenticated users exploit CVE-2016-10709?
Remote authenticated users can exploit CVE-2016-10709 by injecting arbitrary OS commands using the '|' character in the status_rrd_graph_img.php graph parameter.
4
Is there a fix for CVE-2016-10709?
Yes, upgrading to a version of pfSense beyond 2.2.6 will fix CVE-2016-10709.
5
Where can I find more information about CVE-2016-10709?
More information about CVE-2016-10709 can be found at the following references: [1] [2] [3].