ZDI-25-979: Netgate pfSense CE Suricata Path Traversal Remote Code Execution Vulnerability
This vulnerability allows remote attackers to create arbitrary files on affected installations of Netgate pfSense. Authentication is required to exploit this vulnerability. The specific flaw exists within the Suricata package. The issue results from the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to create files in the context of root.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-979?
The vulnerability ZDI-25-979 has a CVSS rating of 8.8, indicating a high severity level.
How do I fix ZDI-25-979?
To mitigate ZDI-25-979, it is recommended to apply any available patches or updates provided by Netgate for pfSense.
Who can exploit ZDI-25-979?
ZDI-25-979 can be exploited by remote attackers who have authenticated access to the affected installations of Netgate pfSense.
What impact does ZDI-25-979 have on pfSense?
The impact of ZDI-25-979 allows attackers to create arbitrary files on affected installations, which can lead to further system compromise.
Is authentication required to exploit ZDI-25-979?
Yes, authentication is required to exploit the vulnerability ZDI-25-979.