PT-2022-16589 · Openvpn+1 · Openvpn+2
Yutaka Watanabe
·
Published
2022-03-18
·
Updated
2022-04-07
·
CVE-2022-24299
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
pfSense CE versions prior to 2.6.0
pfSense Plus versions prior to 22.01
Description
The issue is related to improper input validation, allowing a remote attacker with the privilege to change OpenVPN client or server settings to execute an arbitrary command. This can be done by exploiting the vulnerability in the OpenVPN client or server settings.
Recommendations
For pfSense CE versions prior to 2.6.0, update to version 2.6.0 or later to resolve the issue.
For pfSense Plus versions prior to 22.01, update to version 22.01 or later to resolve the issue.
As a temporary workaround, consider restricting access to the OpenVPN client or server settings until a patch is available.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Openvpn
Pfsense Ce
Pfsense Plus