CVE-2019-16701

pfsense/pfsense
on github

Published

Severity

CVSS v3:
8.8 HIGH
CVSS v2:
9 HIGH

Description

pfSense through 2.3.4 through 2.4.4-p3 allows Remote Code Injection via a methodCall XML document with a pfsense.exec_php call containing shell metacharacters in a parameter value.

References

Configurations

CPE23Version StartVersion EndExact Version
cpe:2.3:a:netgate:pfsense:2.4.4:p1:*:*:*:*:*:*n/an/a2.4.4
cpe:2.3:a:netgate:pfsense:2.4.4:p3:*:*:*:*:*:*n/an/a2.4.4
cpe:2.3:a:netgate:pfsense:2.4.4:p2:*:*:*:*:*:*n/an/a2.4.4
cpe:2.3:a:netgate:pfsense:2.4.4:-:*:*:*:*:*:*n/an/a2.4.4
cpe:2.3:a:netgate:pfsense:*:*:*:*:*:*:*:*2.3.4 (including)2.4.4*

External Links