CVE-2019-11816: High severity netgate pfsense community edition vulnerability
Incorrect access control in the WebUI in OPNsense before version 19.1.8, and pfsense before 2.4.4-p3 allows remote authenticated users to escalate privileges to administrator via a specially crafted request.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2019-11816?
CVE-2019-11816 is a vulnerability that allows remote authenticated users to escalate privileges to administrator via a specially crafted request in the WebUI in OPNsense before version 19.1.8 and pfsense before 2.4.4-p3.
How does CVE-2019-11816 affect OPNsense and pfSense?
CVE-2019-11816 affects OPNsense before version 19.1.8 and pfSense before version 2.4.4-p3.
What is the severity level of CVE-2019-11816?
CVE-2019-11816 has a severity level of 7.2 (high).
How can I fix CVE-2019-11816?
To fix CVE-2019-11816, update OPNsense to version 19.1.8 or later, and update pfSense to version 2.4.4-p3 or later.
Where can I find more information about CVE-2019-11816?
You can find more information about CVE-2019-11816 at the following references: [link1](https://forum.opnsense.org/index.php?topic=12787.0), [link2](https://www.netgate.com/blog/pfsense-2-4-4-release-p3-now-available.html).