PT-2023-11526 · Suricata+3 · Suricata+3
Nguyen Quoc Viet
+1
·
Published
2013-12-28
·
Updated
2025-02-12
·
CVE-2020-19678
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Pfsense version 2.1.3
Pfsense Suricata version 1.4.6 pkg version 1.0.1
Description
A Directory Traversal issue allows a remote attacker to obtain sensitive information via the
file parameter to the "suricata/suricata logs browser.php" endpoint. This enables access to files outside the intended directory, potentially revealing confidential data.Recommendations
For Pfsense version 2.1.3, update to a version that fixes this issue.
For Pfsense Suricata version 1.4.6 pkg version 1.0.1, update to a version that fixes this issue.
As a temporary workaround, consider restricting access to the "suricata/suricata logs browser.php" endpoint to minimize the risk of exploitation.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Pfsense
Pfsense Suricata
Suricata