CVE Vulnerabilities

CVE-2023-29975

Improper Authentication

Published: Nov 09, 2023 | Modified: Nov 21, 2024
CVSS 3.x
7.2
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

An issue discovered in Pfsense CE version 2.6.0 allows attackers to change the password of any user without verification.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

NameVendorStart VersionEnd Version
PfsensePfsense2.6.0 (including)2.6.0 (including)

Potential Mitigations

References