peter bassill · operator
$ cve CVE-2023-27100 JSON

CVE-2023-27100 EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 9.8% (pctl 95)

Patch early

A public exploit exists.

Description

Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE software v2.6.0 allows attackers to bypass brute force protection mechanisms via crafted web requests.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS9.84% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-307
On CISA KEVno
Public exploityes
Published2023-03-22
Last modified2026-06-17

Affected (2)

VendorProduct
netgatepfsense plus
pfsensepfsense

Public exploits

SourceTitleDate
exploit-dbpfsenseCE v2.6.0 - Anti-brute force protection bypass2023-04-08

References

→ the Explorer  ·  watch your stack  ·  NVD