CVE-2023-29974: Critical severity pfsense vulnerability
Published Nov 8, 2023
·Updated
An issue discovered in Pfsense CE version 2.6.0 allows attackers to compromise user accounts via weak password requirements.
Affected Software
1 affected component
pfSense pfSense=2.6.0
Event History
Nov 8, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-29974?
The severity of CVE-2023-29974 is critical with a severity value of 9.8.
2
What is the affected software in CVE-2023-29974?
The affected software in CVE-2023-29974 is Pfsense CE version 2.6.0.
3
How can attackers compromise user accounts in CVE-2023-29974?
Attackers can compromise user accounts in CVE-2023-29974 by exploiting weak password requirements.
4
Is there a fix available for CVE-2023-29974?
Yes, a fix is available for CVE-2023-29974. It is recommended to update to a version that addresses the weak password requirements.
5
Where can I find more information about CVE-2023-29974?
You can find more information about CVE-2023-29974 on the following website: https://www.esecforte.com/cve-2023-29974-weak-password-policy/