PT-2026-73234 · Netgate+1 · Pfsense Plus+1
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
pfSense Plus versions prior to 26.07
Description
The wg(4) driver fails to verify if the MAC verification step succeeded after receiving a decryption result from OCF. This allows the driver to silently accept packets containing an invalid Poly1305 authentication tag. A remote attacker capable of sending UDP packets to a WireGuard endpoint and guessing the receiver's replay window bounds can inject forged or modified transport data packets into the tunnel. Additionally, an attacker intercepting packets bound for a FreeBSD host can modify the ciphertext and authenticated data without being detected by the receiver.
Recommendations
Update pfSense Plus to version 26.07.
Fix
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Freebsd
Pfsense Plus