CVE-2023-27152: Critical severity opnsense vulnerability
Published Oct 23, 2023
·Updated
DECISO OPNsense 23.1 does not impose rate limits for authentication, allowing attackers to perform a brute-force attack to bypass authentication.
Affected Software
1 affected component
OPNsense OPNsense=23.1
Event History
Oct 23, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2023-27152?
CVE-2023-27152 is a vulnerability in DECISO OPNsense 23.1 that allows attackers to perform a brute-force attack to bypass authentication.
2
How severe is CVE-2023-27152?
The severity rating of CVE-2023-27152 is critical with a CVSS score of 9.8.
3
How does CVE-2023-27152 impact Opnsense Opnsense 23.1?
CVE-2023-27152 impacts Opnsense Opnsense 23.1 by not imposing rate limits for authentication, which allows attackers to perform brute-force attacks.
4
What is the Common Weakness Enumeration (CWE) of CVE-2023-27152?
The CWE of CVE-2023-27152 is CWE-307 (Improper Restriction of Excessive Authentication Attempts).
5
Is there a fix available for CVE-2023-27152?
To fix CVE-2023-27152, it is recommended to update to a version of DECISO OPNsense that imposes rate limits for authentication.