First published: Mon Oct 23 2023(Updated: )
DECISO OPNsense 23.1 does not impose rate limits for authentication, allowing attackers to perform a brute-force attack to bypass authentication.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OPNsense OPNsense | =23.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-27152 is a vulnerability in DECISO OPNsense 23.1 that allows attackers to perform a brute-force attack to bypass authentication.
The severity rating of CVE-2023-27152 is critical with a CVSS score of 9.8.
CVE-2023-27152 impacts Opnsense Opnsense 23.1 by not imposing rate limits for authentication, which allows attackers to perform brute-force attacks.
The CWE of CVE-2023-27152 is CWE-307 (Improper Restriction of Excessive Authentication Attempts).
To fix CVE-2023-27152, it is recommended to update to a version of DECISO OPNsense that imposes rate limits for authentication.