CVE-2022-40624: OS Command Injection
Published Dec 20, 2022
·Updated
pfSense pfBlockerNG through 2.1.427 allows remote attackers to execute arbitrary OS commands as root via the HTTP Host header, a different vulnerability than CVE-2022-31814.
Affected Software
1 affected component
pfSense pfBlockerNG<2.1.4_27
Event History
Dec 20, 2022
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2022-40624?
CVE-2022-40624 is a vulnerability in pfSense pfBlockerNG that allows remote attackers to execute arbitrary OS commands as root via the HTTP Host header.
2
What is the severity of CVE-2022-40624?
CVE-2022-40624 has a severity rating of critical with a CVSS score of 9.8.
3
How does CVE-2022-40624 affect pfSense pfBlockerNG?
CVE-2022-40624 affects pfSense pfBlockerNG version up to 2.1.4_27.
4
What is the Common Weakness Enumeration (CWE) for CVE-2022-40624?
CVE-2022-40624 is associated with CWE-78, which is Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection').
5
How can I fix the CVE-2022-40624 vulnerability in pfSense pfBlockerNG?
To fix the CVE-2022-40624 vulnerability in pfSense pfBlockerNG, update to a version above 2.1.4_27 as recommended by the vendor.