CVE-2022-31814: OS Command Injection
Published Sep 5, 2022
·Updated
pfSense pfBlockerNG through 2.1.426 allows remote attackers to execute arbitrary OS commands as root via shell metacharacters in the HTTP Host header. NOTE: 3.x is unaffected.
Affected Software
1 affected component
Netgate Pfblockerng Pfsense<=2.1.4_26
Event History
Sep 5, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this pfSense pfBlockerNG vulnerability?
The vulnerability ID for this pfSense pfBlockerNG vulnerability is CVE-2022-31814.
2
What is the severity of CVE-2022-31814?
The severity of CVE-2022-31814 is critical with a CVSS score of 9.8.
3
How does CVE-2022-31814 impact pfSense pfBlockerNG?
CVE-2022-31814 allows remote attackers to execute arbitrary OS commands as root via shell metacharacters in the HTTP Host header.
4
Which version of pfSense pfBlockerNG is affected by CVE-2022-31814?
Version 2.1.4_26 of pfSense pfBlockerNG is affected by CVE-2022-31814.
5
Is pfSense pfBlockerNG version 3.x affected by CVE-2022-31814?
No, pfSense pfBlockerNG version 3.x is unaffected by CVE-2022-31814.