Improper input validation vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software versions prior to 22.01) allows a remote attacker with the privilege to change OpenVPN client or server settings to execute an arbitrary command.
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
Link | Tags |
---|---|
https://jvn.jp/en/jp/JVN87751554/index.html | third party advisory patch |
https://docs.netgate.com/downloads/pfSense-SA-22_03.webgui.asc | patch vendor advisory mitigation |