Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds are vulnerable to command injection in the OpenVPN widget due to improper sanitization of user-supplied input to the OpenVPN management interface. An authenticated attacker can exploit this vulnerability by injecting arbitrary OpenVPN management commands via the remipp parameter.
References
Configurations
No configuration.
History
17 May 2025, 13:15
Type | Values Removed | Values Added |
---|---|---|
References |
|
|
16 May 2025, 14:43
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
14 May 2025, 15:15
Type | Values Removed | Values Added |
---|---|---|
CWE | CWE-94 | |
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
14 May 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-05-14 14:15
Updated : 2025-05-17 13:15
NVD link : CVE-2024-54780
Mitre link : CVE-2024-54780
CVE.ORG link : CVE-2024-54780
JSON object : View
Products Affected
No product.
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')