THREATINT

We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Zendesk (Helpdesk and Chat)

Ok

PUBLISHED

CVE-2022-31814

Reserved:2022-05-31
Published:2022-09-05
Updated:2024-05-13

Description

pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metacharacters in the HTTP Host header. NOTE: 3.x is unaffected.

References

https://docs.netgate.com/pfsense/en/latest/packages/pfblocker.html

https://www.ihteam.net/advisory/pfblockerng-unauth-rce-vulnerability/

http://packetstormsecurity.com/files/168743/pfSense-pfBlockerNG-2.1.4_26-Shell-Upload.html

http://packetstormsecurity.com/files/171123/pfBlockerNG-2.1.4_26-Remote-Code-Execution.html

https://github.com/pfsense/FreeBSD-ports/pull/1169

https://github.com/pfsense/FreeBSD-ports/pull/1169/commits/071bdcf2d918c3e51cde11cf81fbd9b6f0379d7e

cve.org CVE-2022-31814

nvd.nist.gov CVE-2022-31814

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2022-31814