OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 was discovered to contain insecure permissions in the directory /tmp.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Link | Tags |
---|---|
http://opnsense.com | product |
https://logicaltrust.net/blog/2023/08/opnsense.html | third party advisory exploit |