CVE-2023-29975: High severity pfsense vulnerability
Published Nov 9, 2023
·Updated
An issue discovered in Pfsense CE version 2.6.0 allows attackers to change the password of any user without verification.
Affected Software
1 affected component
pfSense pfSense=2.6.0
Event History
Nov 9, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2023-29975.
2
What is the severity of CVE-2023-29975?
The severity of CVE-2023-29975 is high with a severity value of 7.2.
3
What is the affected software version of CVE-2023-29975?
The affected software version of CVE-2023-29975 is Pfsense CE version 2.6.0.
4
How can attackers exploit CVE-2023-29975?
Attackers can exploit CVE-2023-29975 by changing the password of any user without verification.
5
Is there a reference link for CVE-2023-29975?
Yes, you can find more information about CVE-2023-29975 at https://www.esecforte.com/cve-2023-29975-unverified-password-changed/