ZeroHour

CVE-2023-27100

CVSS 3.1
9.8 critical
EPSS
10%p95
Published
()
Modified
Description

Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE software v2.6.0 allows attackers to bypass brute force protection mechanisms via crafted web requests.

Vendors
netgatepfsense
Products
pfsense plus, pfsense
Weakness
CWE-307
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.