Vulnerabilities > Netgate

DATE CVE VULNERABILITY TITLE RISK
2019-06-25 CVE-2019-12949 Cross-site Scripting vulnerability in Netgate Pfsense 2.4.4
In pfSense 2.4.4-p2 and 2.4.4-p3, if it is possible to trick an authenticated administrator into clicking on a button on a phishing page, an attacker can leverage XSS to upload arbitrary executable code, via diag_command.php and rrd_fetch_json.php (timePeriod parameter), to a server.
network
netgate CWE-79
4.3
2019-06-03 CVE-2019-12585 OS Command Injection vulnerability in multiple products
Apcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an Arbitrary Command Execution issue in apcupsd_status.php.
network
low complexity
apcupsd netgate CWE-78
7.5
2019-06-03 CVE-2019-12584 Cross-site Scripting vulnerability in multiple products
Apcupsd 0.3.91_5, as used in pfSense through 2.4.4-RELEASE-p3 and other products, has an XSS issue in apcupsd_status.php.
4.3
2019-05-29 CVE-2019-12347 Cross-site Scripting vulnerability in Netgate Pfsense 2.4.4
In pfSense 2.4.4-p3, a stored XSS vulnerability occurs when attackers inject a payload into the Name or Description field via an acme_accountkeys_edit.php action.
network
netgate CWE-79
4.3
2019-05-20 CVE-2019-11816 Incorrect access control in the WebUI in OPNsense before version 19.1.8, and pfsense before 2.4.4-p3 allows remote authenticated users to escalate privileges to administrator via a specially crafted request.
network
low complexity
netgate opnsense
6.5
2019-03-01 CVE-2018-20799 Unspecified vulnerability in Netgate Pfsense 2.4.4
In pfSense 2.4.4_1, blocking of source IP addresses on the basis of failed HTTPS authentication is inconsistent with blocking of source IP addresses on the basis of failed SSH authentication (the behavior does not match the sshguard documentation), which might make it easier for attackers to bypass intended access restrictions.
network
low complexity
netgate
5.0
2019-03-01 CVE-2018-20798 Incorrect Permission Assignment for Critical Resource vulnerability in Netgate Pfsense 2.4.4
The expiretable configuration in pfSense 2.4.4_1 establishes block durations that are incompatible with the block durations implemented by sshguard, which might make it easier for attackers to bypass intended access restrictions.
network
low complexity
netgate CWE-732
5.0
2019-02-20 CVE-2019-8953 Cross-site Scripting vulnerability in Netgate Haproxy
The HAProxy package before 0.59_16 for pfSense has XSS via the desc (aka Description) or table_actionsaclN parameter, related to haproxy_listeners.php and haproxy_listeners_edit.php.
network
netgate CWE-79
4.3
2018-12-03 CVE-2018-4021 OS Command Injection vulnerability in Netgate Pfsense 2.4.4
An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POST request.
network
low complexity
netgate CWE-78
6.5
2018-12-03 CVE-2018-4020 OS Command Injection vulnerability in Netgate Pfsense 2.4.4
An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POST request.
network
low complexity
netgate CWE-78
6.5