PT-2023-26723 · Opnsense · Opnsense Community Edition+1

Feliks Penconek

·

Published

2023-08-09

·

Updated

2023-10-10

·

CVE-2023-38998

CVSS v3.1

6.1

Medium

VectorAV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions OPNsense Community Edition versions prior to 23.7 OPNsense Business Edition versions prior to 23.4.2
Description The issue is an open redirect in the Login page of OPNsense, allowing attackers to redirect a victim user to an arbitrary web site via a crafted URL.
Recommendations For OPNsense Community Edition versions prior to 23.7, update to version 23.7 or later. For OPNsense Business Edition versions prior to 23.4.2, update to version 23.4.2 or later.

Exploit

Fix

Open Redirect

Weakness Enumeration

Related Identifiers

CVE-2023-38998

Affected Products

Opnsense Business Edition
Opnsense Community Edition