First published: Mon Jan 22 2018(Updated: )
pfSense before 2.3 allows remote authenticated users to execute arbitrary OS commands via a '|' character in the status_rrd_graph_img.php graph parameter, related to _rrd_graph_img.php.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
pfSense pfSense | <=2.2.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2016-10709 is critical with a CVSS score of 8.8.
CVE-2016-10709 affects pfSense versions up to and including 2.2.6.
Remote authenticated users can exploit CVE-2016-10709 by injecting arbitrary OS commands using the '|' character in the status_rrd_graph_img.php graph parameter.
Yes, upgrading to a version of pfSense beyond 2.2.6 will fix CVE-2016-10709.
More information about CVE-2016-10709 can be found at the following references: [1] [2] [3].