CVE Vulnerabilities

CVE-2023-29975

Improper Authentication

Published: Nov 09, 2023 | Modified: Nov 16, 2023
CVSS 3.x
7.2
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

An issue discovered in Pfsense CE version 2.6.0 allows attackers to change the password of any user without verification.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Pfsense Pfsense 2.6.0 (including) 2.6.0 (including)

Potential Mitigations

References