Vulnerability Description
pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metacharacters in the HTTP Host header. NOTE: 3.x is unaffected.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Netgate | Pfblockerng | <= 2.1.4_26 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/168743/pfSense-pfBlockerNG-2.1.4_26-Shell-UExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/171123/pfBlockerNG-2.1.4_26-Remote-Code-Exe
- https://docs.netgate.com/pfsense/en/latest/packages/pfblocker.htmlRelease NotesVendor Advisory
- https://github.com/pfsense/FreeBSD-ports/pull/1169
- https://github.com/pfsense/FreeBSD-ports/pull/1169/commits/071bdcf2d918c3e51cde1
- https://www.ihteam.net/advisory/pfblockerng-unauth-rce-vulnerability/ExploitTechnical DescriptionThird Party Advisory
- http://packetstormsecurity.com/files/168743/pfSense-pfBlockerNG-2.1.4_26-Shell-UExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/171123/pfBlockerNG-2.1.4_26-Remote-Code-Exe
- https://docs.netgate.com/pfsense/en/latest/packages/pfblocker.htmlRelease NotesVendor Advisory
- https://github.com/pfsense/FreeBSD-ports/pull/1169
- https://github.com/pfsense/FreeBSD-ports/pull/1169/commits/071bdcf2d918c3e51cde1
- https://www.ihteam.net/advisory/pfblockerng-unauth-rce-vulnerability/ExploitTechnical DescriptionThird Party Advisory
FAQ
What is CVE-2022-31814?
CVE-2022-31814 is a vulnerability with a CVSS score of 9.8 (CRITICAL). pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metacharacters in the HTTP Host header. NOTE: 3.x is unaffected.
How severe is CVE-2022-31814?
CVE-2022-31814 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-31814?
Check the references section above for vendor advisories and patch information. Affected products include: Netgate Pfblockerng.