CVE-2023-39001: Command Injection
Published Aug 9, 2023
·Updated
A command injection vulnerability in the component diagbackup.php of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allows attackers to execute arbitrary commands via a crafted backup configuration file.
Affected Software
1 affected component
OPNsense OPNsense<23.7
Remediation
Event History
Aug 9, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is CVE-2023-39001?
CVE-2023-39001 is a command injection vulnerability in the component diag_backup.php of OPNsense before version 23.7.
2
How severe is CVE-2023-39001?
CVE-2023-39001 has a severity rating of critical with a score of 9.8.
3
How can an attacker exploit CVE-2023-39001?
An attacker can exploit CVE-2023-39001 by executing arbitrary commands via a crafted backup configuration file.
4
What is the affected software version of CVE-2023-39001?
CVE-2023-39001 affects OPNsense versions up to and excluding 23.7.
5
How can I fix CVE-2023-39001?
To fix CVE-2023-39001, update OPNsense to version 23.7 or newer.