PT-2019-14752 · Netgate · Pfsense

Published

2019-09-26

·

Updated

2020-07-27

·

CVE-2019-16667

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions pfSense version 2.4.4-p3
Description The issue allows for CSRF, potentially enabling the execution of OS commands. This is demonstrated through the txtCommand or txtRecallBuffer field in the diag command.php file. The csrf callback() function is involved, producing a "CSRF token expired" error along with a Try Again button when a CSRF token is missing.
Recommendations For pfSense version 2.4.4-p3, consider restricting access to the diag command.php file to minimize the risk of exploitation. As a temporary workaround, avoid using the txtCommand or txtRecallBuffer fields in the diag command.php file until a patch is available.

Exploit

Fix

CSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-16667

Affected Products

Pfsense