CVE-2023-39005: High severity opnsense vulnerability
Published Aug 9, 2023
·Updated
Insecure permissions exist for configd.socket in OPNsense Community Edition before 23.7 and Business Edition before 23.4.2.
Affected Software
1 affected component
OPNsense OPNsense<23.7
Event History
Aug 9, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2023-39005.
2
What is the severity of CVE-2023-39005?
The severity of CVE-2023-39005 is high with a severity value of 7.5.
3
Which versions of OPNsense are affected by CVE-2023-39005?
CVE-2023-39005 affects OPNsense Community Edition before version 23.7 and Business Edition before version 23.4.2.
4
What is the CWE ID associated with CVE-2023-39005?
The CWE ID associated with CVE-2023-39005 is 732.
5
How can I fix the insecure permissions in configd.socket?
To fix the insecure permissions in configd.socket, it is recommended to update OPNsense to the latest version.