First published: Wed Aug 09 2023(Updated: )
Insecure permissions in the configuration directory (/conf/) of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allow attackers to access sensitive information (e.g., hashed root password) which could lead to privilege escalation.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
OPNsense OPNsense | <23.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-39004 is a vulnerability in OPNsense Community Edition and Business Edition that allows attackers to access sensitive information and potentially escalate privileges.
CVE-2023-39004 has a severity rating of 9.8, which is considered critical.
CVE-2023-39004 occurs due to insecure permissions in the configuration directory (/conf/) of OPNsense.
The affected software versions for CVE-2023-39004 are OPNsense Community Edition before 23.7 and Business Edition before 23.4.2.
CVE-2023-39004 can be exploited by attackers to access sensitive information, such as hashed root passwords, leading to potential privilege escalation.