First published: Wed Nov 08 2023(Updated: )
An issue discovered in Pfsense CE version 2.6.0 allows attackers to compromise user accounts via weak password requirements.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
pfSense pfSense | =2.6.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-29974 is critical with a severity value of 9.8.
The affected software in CVE-2023-29974 is Pfsense CE version 2.6.0.
Attackers can compromise user accounts in CVE-2023-29974 by exploiting weak password requirements.
Yes, a fix is available for CVE-2023-29974. It is recommended to update to a version that addresses the weak password requirements.
You can find more information about CVE-2023-29974 on the following website: https://www.esecforte.com/cve-2023-29974-weak-password-policy/