CVE-2023-27253: Command Injection
Published Mar 17, 2023
·Updated
A command injection vulnerability in the function restorerrddata() of Netgate pfSense v2.7.0 allows authenticated attackers to execute arbitrary commands via manipulating the contents of an XML file supplied to the component config.xml.
Credit
Emir Polat
Affected Software
1 affected component
Netgate pfSense=2.7.0
Remediation
Patch Available
Event History
Mar 17, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Jul 20, 2023
Exploit Published
12:00 AM
Known Exploited
12:00 AM
Frequently Asked Questions
1
What is the severity of CVE-2023-27253?
CVE-2023-27253 is rated as a high severity vulnerability due to the potential for authenticated attackers to execute arbitrary commands.
2
How can I fix CVE-2023-27253?
To fix CVE-2023-27253, update your Netgate pfSense installation to the latest version that addresses this vulnerability.
3
Who is affected by CVE-2023-27253?
CVE-2023-27253 affects users running Netgate pfSense version 2.7.0.
4
What type of vulnerability is CVE-2023-27253?
CVE-2023-27253 is a command injection vulnerability.
5
What component is vulnerable in CVE-2023-27253?
The vulnerability in CVE-2023-27253 exists in the restore_rrddata() function related to the config.xml file.