Netgate · Pfsense Ce · CVE-2023-48123
**Name of the Vulnerable Software and Affected Versions**
Netgate pfSense Plus versions 23.05.1 and earlier
Netgate pfSense CE version 2.7.0 and earlier
**Description**
The issue allows a remote attacker to execute arbitrary code via a crafted request to the `packet capture.php` file. This enables the attacker to potentially gain control over the system.
**Recommendations**
For Netgate pfSense Plus versions 23.05.1 and earlier, update to a version later than 23.05.1 to resolve the issue.
For Netgate pfSense CE version 2.7.0 and earlier, update to a version later than 2.7.0 to resolve the issue.
As a temporary workaround, consider restricting access to the `packet capture.php` file until a patch is available.