Patch Released for RCE Vulnerability in pfSense Firewall - SOCRadar (2024)

A critical vulnerability has been discovered in a plugin ofNetgate’s pfSense firewall. The flaw is tracked asCVE-2022-31814and can expose the affected instances to unauthenticated remote code execution attacks.

pfSense is an open-source firewall and router software distribution based on FreeBSD. The firewall does not include the plugin named pfBlockerNG by default. pfBlockerNG enables allow-listing in the pfSense firewall, allowing the users to block specific IPs and entire countries.

To become exposed, the issue requires access to the web server on the firewall, which should never be open on WAN and is often restricted when configured per best practices.

The vulnerability affects pfBlockerNG versions 2.1.4_26 and earlier, and software updates are available to address the problem.

Patch Released for RCE Vulnerability in pfSense Firewall - SOCRadar (1)

Over 30K pfSense Machines Exposed

The CVSS score of the vulnerability is 9.8, as noted in IHTeam’s advisory since the web server is run by root and exploitable by unauthenticated attackers.

According to Netgate, the overall practical impact was deemed lower even though the issue received a high score. A Shodan search shows over 30,000 pfSense machines are exposed on the internet. And as Netgate also implies, this does not indicate the specific count of instances impacted by the plugin’s vulnerability.

Patch Released for RCE Vulnerability in pfSense Firewall - SOCRadar (2)

The pfSense firewall’s distributor, Netgate, stated that the issue uncovered by the researchers was in the pfBlockerNG package but had previously been addressed in the pfBlockerNG-devel package, the version the package maintainer recommends everyone use.

Developers continue shipping and enabling users to install between the 2.x and the 3.x branch. The researchers said, if the affected 2.x branch was removed entirely from the list of accessible plugins, the misunderstanding could be resolved quickly.

Proof-of-concept isAvailable

Software updates are available from pfSense, and the plugin’s developer, pfBlockerNG-devel, is a secure version recommended.

According to an IHTeam researcher, other software developers could learn from the flaw’s characteristics.

The researcher explained: “To avoid these types of vulnerabilities, developers should take extra care while handling user input (not only via direct GET and POST requests but also via input that might be passed in request headers such as Cookies, Host, or User-Agent). All user input should be carefully analyzed and sanitized before being passed to the application. This is also valid for other attacks such as cross-site scripting (XSS) or SQL injection, not only for command execution.”

The exploit code can be foundhere.

Check IHTeam’sblog postfor a technical description and proof-of-concept of the problem.

Patch Released for RCE Vulnerability in pfSense Firewall - SOCRadar (3)
Patch Released for RCE Vulnerability in pfSense Firewall - SOCRadar (2024)

FAQs

What is the new pfSense vulnerability? ›

pfSense v2. 5.2 was discovered to contain a cross-site scripting (XSS) vulnerability in the browser. php component. This vulnerability allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into a file name.

What are the vulnerabilities in pfSense 2.7 0? ›

pfSense CE 2.7. 0 and below, pfSense Plus 23.05. 1 and below are vulnerable to two XSS vulnerabilities and a Command Injection vulnerability (CVE-2023-42325, CVE-2023-42327, CVE-2023-42326). The security vulnerabilities are fixed in pfSense CE 2.7.

What is the RCE vulnerability in FortiOS? ›

The ASD's ACSC is aware of an Unauthenticated Remote Code Execution (RCE) vulnerability (CVE-2024-21762) in Fortinet FortiOS devices. CVE-2024-21762 refers to an out-of-bounds write vulnerability that may allow Unauthenticated RCE via a specially crafted HTTP request.

What are the disadvantages of pfSense firewall? ›

Challenging web GUI setup and management: Non-expert users may find it challenging to set up and manage the web GUI, particularly when it comes to assigning WAN and LAN interfaces. Limited API and scripting capabilities: Some reviewers have highlighted the lack of an API for making changes in pfSense.

How secure is pfSense firewall? ›

Enhanced Security Monitoring: pfSense, being a powerful open-source firewall and router software, provides robust network security. However, adding Snort enhances security monitoring capabilities by providing an additional layer of defense against intrusions and malicious activities.

What are the 2 new high severity vulnerabilities that OpenSSL releases patch for? ›

The OpenSSL project released version 3.0. 7 on November 1, 2022, to address CVE-2022-3786 and CVE-2022-3602, two high-severity vulnerabilities affecting OpenSSL's 3.0. x version stream discovered and reported by Polar Bear and Viktor Dukhovni.

What is the latest version of pfSense? ›

pfSense
Released to manufacturingOct 2006
Latest releaseCommunity Edition: 2.7.2 (amd64) / December 7, 2023 Plus: 23.09.1 / December 7, 2023
Repositorygithub.com/pfsense/pfsense
Platforms32-bit (discontinued in 2.4.x); 64-bit Intel / AMD
Support status
11 more rows

Which is better, pfSense or OPNsense? ›

If you want high customizability and a large support community, pfSense is a good option. If you prioritize an easy-to-use interface and frequent updates, instead, OPNsense may be better. Ultimately, pfSense offers more flexibility for seasoned users, but OPNsense provides a more polished out-of-box experience.

What is RCE vulnerability? ›

How remote code execution (RCE) attacks work. Remote code execution attacks generally occur via vulnerabilities in web applications and network infrastructure. Remote code execution vulnerabilities are flaws in software that allow an attacker to run malicious code on a target system.

How bad is RCE? ›

RCE vulnerabilities are highly sought after by malicious actors. Exploiting these vulnerabilities can lead to devastating consequences, including data breaches, system compromises, and the propagation of malware or ransomware.

Can you get RCE from XSS? ›

In this article our security experts Tom and Almas explain how they managed to bypass client and server-side defenses in FortiADC, and turn an allegedly harmless XSS into RCE by optimally utilizing an extremely restricted payload space.

What is a new 0day vulnerability? ›

A zero-day vulnerability is unknown to the vendor, and thus there is no patch, mitigation, or fix available to address it. The term “zero-day” refers to the amount of time vendors have to address the flaw before hackers can exploit it.

What is the new Linux kernel vulnerability? ›

CISA has added a new security flaw affecting the Linux kernel to its Known Exploited Vulnerabilities (KEV) catalog. The vulnerability, CVE-2024-1086, allows attackers to elevate their privileges, even allowing the execution of random code.

What is new remote code execution vulnerability? ›

Remote access: RCE vulnerabilities are commonly used to give an attacker an initial foothold on a corporate network that they could then expand. For example, an RCE vulnerability could allow an attacker to steal login credentials that would allow them network access via a VPN.

What's the latest version of pfSense? ›

pfSense
Released to manufacturingOct 2006
Latest releaseCommunity Edition: 2.7.2 (amd64) / December 7, 2023 Plus: 23.09.1 / December 7, 2023
Repositorygithub.com/pfsense/pfsense
Platforms32-bit (discontinued in 2.4.x); 64-bit Intel / AMD
Support status
11 more rows

Top Articles
How to Calculate Cap Rates of Your Short-Term Rental
A Complete List of Different Types of Blockchain Networks
123Movies Encanto
Palm Coast Permits Online
Libiyi Sawsharpener
Ffxiv Palm Chippings
Euro (EUR), aktuální kurzy měn
Boomerang Media Group: Quality Media Solutions
Coffman Memorial Union | U of M Bookstores
Es.cvs.com/Otchs/Devoted
Practical Magic 123Movies
What Auto Parts Stores Are Open
Stl Craiglist
Arrests reported by Yuba County Sheriff
Teamexpress Login
Fnv Turbo
Best Cav Commanders Rok
Hardly Antonyms
Bros Movie Wiki
Palace Pizza Joplin
Studentvue Columbia Heights
Lancasterfire Live Incidents
Invert Clipping Mask Illustrator
Labby Memorial Funeral Homes Leesville Obituaries
Zoe Mintz Adam Duritz
Www Craigslist Com Bakersfield
Hewn New Bedford
Babbychula
Watertown Ford Quick Lane
Culver's.comsummerofsmiles
Truvy Back Office Login
Narragansett Bay Cruising - A Complete Guide: Explore Newport, Providence & More
Farm Equipment Innovations
Paradise Point Animal Hospital With Veterinarians On-The-Go
Page 2383 – Christianity Today
Deepwoken: Best Attunement Tier List - Item Level Gaming
Robert A McDougal: XPP Tutorial
Kacey King Ranch
Fairwinds Shred Fest 2023
NIST Special Publication (SP) 800-37 Rev. 2 (Withdrawn), Risk Management Framework for Information Systems and Organizations: A System Life Cycle Approach for Security and Privacy
Sedano's Supermarkets Expands to Orlando - Sedano's Supermarkets
Lichen - 1.17.0 - Gemsbok! Antler Windchimes! Shoji Screens!
Snohomish Hairmasters
Thanksgiving Point Luminaria Promo Code
Daly City Building Division
Noaa Marine Weather Forecast By Zone
No Boundaries Pants For Men
Top 40 Minecraft mods to enhance your gaming experience
Rise Meadville Reviews
Epower Raley's
ats: MODIFIED PETERBILT 389 [1.31.X] v update auf 1.48 Trucks Mod für American Truck Simulator
Latest Posts
Article information

Author: Laurine Ryan

Last Updated:

Views: 6374

Rating: 4.7 / 5 (77 voted)

Reviews: 84% of readers found this page helpful

Author information

Name: Laurine Ryan

Birthday: 1994-12-23

Address: Suite 751 871 Lissette Throughway, West Kittie, NH 41603

Phone: +2366831109631

Job: Sales Producer

Hobby: Creative writing, Motor sports, Do it yourself, Skateboarding, Coffee roasting, Calligraphy, Stand-up comedy

Introduction: My name is Laurine Ryan, I am a adorable, fair, graceful, spotless, gorgeous, homely, cooperative person who loves writing and wants to share my knowledge and understanding with you.