Vulnerability CVE-2023-27100


Published: 2023-03-22   Modified: 2023-03-23

Description:
Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE software v2.6.0 allows attackers to bypass brute force protection mechanisms via crafted web requests.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
pfsenseCE 2.6.0 Protection Bypass
FabDotNET
10.04.2023

 References:
https://redmine.pfsense.org/issues/13574
https://docs.netgate.com/downloads/pfSense-SA-23_05.sshguard.asc

Copyright 2024, cxsecurity.com

 

Back to Top