CVE-2023-39004

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
09/08/2023
Last modified:
10/10/2023

Description

Insecure permissions in the configuration directory (/conf/) of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allow attackers to access sensitive information (e.g., hashed root password) which could lead to privilege escalation.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:opnsense:opnsense:*:*:*:*:*:*:*:* 23.7 (excluding)