Security Features in pfsense - CVE-2018-20798

 

Security Features in pfsense - CVE-2018-20798

Published: March 1, 2019 / Updated: August 8, 2020


Vulnerability identifier: #VU36084
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-20798
CWE-ID: CWE-254
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote non-authenticated attacker to manipulate data.

The expiretable configuration in pfSense 2.4.4_1 establishes block durations that are incompatible with the block durations implemented by sshguard, which might make it easier for attackers to bypass intended access restrictions.


Affected software

pfsense

How to mitigate CVE-2018-20798

Install update from vendor's website.


External References

Related Security Bulletins