CVE-2023-42326: Command Injection
Published Nov 14, 2023
·Updated
An issue in Netgate pfSense v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the interfacesgifedit.php and interfacesgreedit.php components.
Affected Software
4 affected components
Netgate pfSense<=2.7.0
Netgate pfSense Plus<=23.05.1
pfSense pfSense=2.7.0
pfSense pfSense Plus=23.05.01
Event History
Nov 14, 2023
CVE Published
12:00 AM
Data Sourced
12:00 AM
Description
Dec 12, 2023
News Published
02:00 PM
Frequently Asked Questions
1
What is the severity of CVE-2023-42326?
The severity of CVE-2023-42326 is high with a CVSS score of 8.8.
2
How can an attacker exploit CVE-2023-42326?
An attacker can exploit CVE-2023-42326 by sending a crafted request to the interfaces_gif_edit.php and interfaces_gre_edit.php components in Netgate pfSense v.2.7.0.
3
Which versions of Netgate pfSense are affected by CVE-2023-42326?
Netgate pfSense version 2.7.0 and Netgate pfSense Plus version 23.05.1 are affected by CVE-2023-42326.
4
Can a remote attacker execute arbitrary code using CVE-2023-42326?
Yes, a remote attacker can execute arbitrary code using CVE-2023-42326.
5
Is there a fix available for CVE-2023-42326?
Yes, a fix is available for CVE-2023-42326. Please refer to the official documentation for more information.