Sploitus

CVE-2023-27253

4 known exploits for CVE-2023-27253

A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attackers to execute arbitrary commands via manipulating the contents of an XML file supplied to the component config.xml.

Affected products
Pfsense
Netgate Pfsense
= 2.7.0
Fix
Available
CVSS 3.1
8.8 HIGH
EPSS
89.5% (100th percentile)
Weakness
CWE-91
NVD status
Modified
Published
2023-03-17
CVE-2023-27253 at NVD
Authoritative description, scoring and affected products

4 known exploits for CVE-2023-27253

Proof-of-concept code and exploit modules indexed by Sploitus