ZeroHour

CVE-2023-39004

PoC
CVSS 3.1
9.8 critical
EPSS
<1%p61
Published
()
Modified
Description

Insecure permissions in the configuration directory (/conf/) of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allow attackers to access sensitive information (e.g., hashed root password) which could lead to privilege escalation.

Vendors
opnsense
Products
opnsense
Weakness
CWE-732
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.