CVE-2023-38997: Path Traversal
Published Aug 9, 2023
·Updated
A directory traversal vulnerability in the Captive Portal templates of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to execute arbitrary system commands as root via a crafted ZIP archive.
Affected Software
1 affected component
OPNsense OPNsense<23.7
Remediation
Event History
Aug 9, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this OPNsense vulnerability?
The vulnerability ID for this OPNsense vulnerability is CVE-2023-38997.
2
What is the severity of CVE-2023-38997?
The severity of CVE-2023-38997 is critical with a CVSS score of 9.8.
3
How does the directory traversal vulnerability in OPNsense before 23.7 affect the system?
The directory traversal vulnerability in OPNsense before 23.7 allows attackers to execute arbitrary system commands as root.
4
What software version is affected by CVE-2023-38997?
The OPNsense software version up to exclusive version 23.7 is affected by CVE-2023-38997.
5
How can I fix the directory traversal vulnerability in OPNsense?
To fix the directory traversal vulnerability in OPNsense, update to version 23.7 or later.