PT-2023-22498 · Unknown · Pfsense Ce

Published

2023-10-24

·

Updated

2023-10-31

·

CVE-2023-29973

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Pfsense CE version 2.6.0
Description The issue is related to the absence of a rate limit, which can be exploited by an attacker to create multiple malicious users in the firewall. This can lead to potential security breaches.
Recommendations For Pfsense CE version 2.6.0, consider restricting access to user creation functionality until a patch is available. As a temporary workaround, implement manual monitoring and limits on user creation to minimize the risk of exploitation.

Exploit

Fix

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

CVE-2023-29973

Affected Products

Pfsense Ce