PT-2023-22498 · Unknown · Pfsense Ce

CVE-2023-29973

·

Published

2023-10-24

·

Updated

2023-10-31

CVSS v3.1

4.9

Medium

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Pfsense CE version 2.6.0
Description The issue is related to the absence of a rate limit, which can be exploited by an attacker to create multiple malicious users in the firewall. This can lead to potential security breaches.
Recommendations For Pfsense CE version 2.6.0, consider restricting access to user creation functionality until a patch is available. As a temporary workaround, implement manual monitoring and limits on user creation to minimize the risk of exploitation.

Exploit

Fix

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2023-29973

Affected Products

Pfsense Ce