First published: Mon May 20 2019(Updated: )
Incorrect access control in the WebUI in OPNsense before version 19.1.8, and pfsense before 2.4.4-p3 allows remote authenticated users to escalate privileges to administrator via a specially crafted request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netgate pfSense | <=2.4.4 | |
Netgate pfSense | =2.4.4-p1 | |
Netgate pfSense | =2.4.4-p2 | |
OPNsense OPNsense | <19.1.8 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-11816 is a vulnerability that allows remote authenticated users to escalate privileges to administrator via a specially crafted request in the WebUI in OPNsense before version 19.1.8 and pfsense before 2.4.4-p3.
CVE-2019-11816 affects OPNsense before version 19.1.8 and pfSense before version 2.4.4-p3.
CVE-2019-11816 has a severity level of 7.2 (high).
To fix CVE-2019-11816, update OPNsense to version 19.1.8 or later, and update pfSense to version 2.4.4-p3 or later.
You can find more information about CVE-2019-11816 at the following references: [link1](https://forum.opnsense.org/index.php?topic=12787.0), [link2](https://www.netgate.com/blog/pfsense-2-4-4-release-p3-now-available.html).