Insecure permissions exist for configd.socket in OPNsense Community Edition before 23.7 and Business Edition before 23.4.2.
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
Link | Tags |
---|---|
https://github.com/opnsense/core/issues/6647 | vendor advisory issue tracking exploit |
https://logicaltrust.net/blog/2023/08/opnsense.html | third party advisory exploit |