An issue discovered in Pfsense CE version 2.6.0 allows attackers to compromise user accounts via weak password requirements.
The product does not require that users should have strong passwords, which makes it easier for attackers to compromise user accounts.
Link | Tags |
---|---|
https://www.esecforte.com/cve-2023-29974-weak-password-policy/ | third party advisory |