CVE-2019-16701

Severity CVSS v4.0:
Pending analysis
Type:
CWE-78 OS Command Injections
Publication date:
25/09/2019
Last modified:
25/09/2019

Description

pfSense through 2.3.4 through 2.4.4-p3 allows Remote Code Injection via a methodCall XML document with a pfsense.exec_php call containing shell metacharacters in a parameter value.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:netgate:pfsense:*:*:*:*:*:*:*:* 2.3.4 (including) 2.4.4 (excluding)
cpe:2.3:a:netgate:pfsense:2.4.4:-:*:*:*:*:*:*
cpe:2.3:a:netgate:pfsense:2.4.4:p1:*:*:*:*:*:*
cpe:2.3:a:netgate:pfsense:2.4.4:p2:*:*:*:*:*:*
cpe:2.3:a:netgate:pfsense:2.4.4:p3:*:*:*:*:*:*