CVE-2024-57273: XSS
Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds is vulnerable to Cross-site scripting (XSS) in the Automatic Configuration Backup (ACB) service, allowing remote attackers to execute arbitrary JavaScript, delete backups, or leak sensitive information via an unsanitized "reason" field and a derivable device key generated from the public SSH key.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Netgate pfSense CE and corresponding Plus buildsto a version that resolves this vulnerability.Fixed in 2.8.0 beta
Event History
Frequently Asked Questions
What is the severity of CVE-2024-57273?
CVE-2024-57273 is classified as a medium severity vulnerability due to its potential for remote exploitation via cross-site scripting.
How do I fix CVE-2024-57273?
To mitigate CVE-2024-57273, upgrade to Netgate pfSense CE version 2.8.0 or later.
What type of vulnerability is CVE-2024-57273?
CVE-2024-57273 is a Cross-site scripting (XSS) vulnerability affecting the Automatic Configuration Backup service.
Which versions of pfSense are affected by CVE-2024-57273?
All versions of Netgate pfSense CE prior to 2.8.0 beta release are affected by CVE-2024-57273.
What are the potential impacts of CVE-2024-57273?
CVE-2024-57273 could allow an attacker to execute arbitrary JavaScript, delete backups, or leak sensitive information.