First published: Mon Sep 05 2022(Updated: )
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metacharacters in the HTTP Host header. NOTE: 3.x is unaffected.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Netgate Pfblockerng | <=2.1.4_26 | |
<=2.1.4_26 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this pfSense pfBlockerNG vulnerability is CVE-2022-31814.
The severity of CVE-2022-31814 is critical with a CVSS score of 9.8.
CVE-2022-31814 allows remote attackers to execute arbitrary OS commands as root via shell metacharacters in the HTTP Host header.
Version 2.1.4_26 of pfSense pfBlockerNG is affected by CVE-2022-31814.
No, pfSense pfBlockerNG version 3.x is unaffected by CVE-2022-31814.