First published: Tue Dec 20 2022(Updated: )
pfSense pfBlockerNG through 2.1.4_27 allows remote attackers to execute arbitrary OS commands as root via the HTTP Host header, a different vulnerability than CVE-2022-31814.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
pfSense pfBlockerNG | <2.1.4_27 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-40624 is a vulnerability in pfSense pfBlockerNG that allows remote attackers to execute arbitrary OS commands as root via the HTTP Host header.
CVE-2022-40624 has a severity rating of critical with a CVSS score of 9.8.
CVE-2022-40624 affects pfSense pfBlockerNG version up to 2.1.4_27.
CVE-2022-40624 is associated with CWE-78, which is Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection').
To fix the CVE-2022-40624 vulnerability in pfSense pfBlockerNG, update to a version above 2.1.4_27 as recommended by the vendor.