Roughly 1,450 pfSense instances exposed online are vulnerable to command injection and cross-site scripting flaws that, if chained, could enable attackers to perform remote code execution on the appliance. pfSense is a popular open-source firewall and router software that allows extensive customization and deployment flexibility. It is a cost-effective solution that accommodates specific needs, offering a wide range of features typically found in expensive commercial products. In mid-November, SonarSource’s researchers with the aid of their SonarCloud solution discovered three flaws impacting pfSense 2.7.0 and older and pfSense Plus 23.05.01 and older. The flaws are tracked as CVE-2023-42325 (XSS), CVE-2023-42327 (XSS), and CVE-2023-42326 (command injection). Although the reflected XSS flaws require user action on the victim’s side to work, the command injection flaw is more severe (CVSS score: 8.8). This vulnerability in pfSense’s web UI arises from shell commands being constructed from user-provided data for configuring network interfaces without applying proper validation. The flaw impacts the "gifif" network interface parameter, which isn’t checked for safe values, allowing malicious actors to inject additional commands in the parameter, leading to their execution with root privileges. For this exploit to work, the threat actor needs access to an account with interface editing permissions, hence the need to chain the flaws together for a powerful attack. Either CVE-2023-...
Over 1,450 pfSense servers exposed to RCE attacks via bug chain
BleepingComputer
·Bill Toulas
·Published Dec 12, 2023
·Updated
Affected Software
2 affected components
pfSense pfSense=2.7.0
pfSense pfSense Plus=23.05.01
Frequently Asked Questions
1
What are the vulnerabilities discussed in the article?
The article discusses command injection and cross-site scripting flaws in pfSense servers.
2
How many pfSense servers are reported to be vulnerable?
Roughly 1,450 pfSense instances are exposed online and vulnerable to attacks.
3
What could attackers achieve by exploiting these vulnerabilities?
If exploited, attackers could achieve remote code execution on the affected pfSense appliances.
4
Which specific versions of pfSense are affected by these vulnerabilities?
The affected versions include pfSense 2.7.0 and pfSense Plus 23.05.01.
5
What security implications arise from the vulnerability chain in pfSense?
The vulnerability chain allows for potential remote exploits, leading to significant security breaches in network setups.