CVE-2017-1000479
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
pfSense versions 2.4.1 and lower are vulnerable to clickjacking attacks in the CSRF error page resulting in privileged execution of arbitrary code, because the error detection occurs before an X-Frame-Options header is set. This is fixed in 2.4.2-RELEASE. OPNsense, a 2015 fork of pfSense, was not vulnerable since version 16.1.16 released on June 06, 2016. The unprotected web form was removed from the code during an internal security audit under "possibly insecure" suspicions.
pfSense, en sus versiones 2.4.1 y anteriores, es vulnerable a ataques de secuestro de clics en la página de error CSRF. Esto resulta en la ejecución con privilegios de código arbitrario. Consulte la primera URL de referencia para más detalles. Los créditos corresponden a Yorick Koster. OPNsense, una copia (fork) del 2015 de pfSense, no fue vulnerable desde la versión 16.1.16 publicada el 6 de junio de 2016. El formulario web desprotegido se eliminó del código durante una auditoría interna de seguridad bajo sospechas de "probablemente inseguro".
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-01-03 CVE Reserved
- 2018-01-03 CVE Published
- 2023-12-14 EPSS Updated
- 2024-08-05 CVE Updated
- 2024-08-05 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-352: Cross-Site Request Forgery (CSRF)
CAPEC
References (7)
URL | Date | SRC |
---|---|---|
http://www.openwall.com/lists/oss-security/2017/11/22/7 | 2024-08-05 | |
https://www.securify.nl/en/advisory/SFY20171101/clickjacking-vulnerability-in-csrf-error-page-pfsense.html | 2024-08-05 |
URL | Date | SRC |
---|---|---|
https://github.com/opnsense/core/commit/d218b225 | 2019-05-30 | |
https://github.com/pfsense/pfsense/commit/386d89b07 | 2019-05-30 |
URL | Date | SRC |
---|---|---|
https://doc.pfsense.org/index.php/2.4.2_New_Features_and_Changes | 2017-11-21 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Netgate Search vendor "Netgate" | Pfsense Search vendor "Netgate" for product "Pfsense" | <= 2.4.1 Search vendor "Netgate" for product "Pfsense" and version " <= 2.4.1" | - |
Affected
| ||||||
Opnsense Project Search vendor "Opnsense Project" | Opnsense Search vendor "Opnsense Project" for product "Opnsense" | < 16.1.16 Search vendor "Opnsense Project" for product "Opnsense" and version " < 16.1.16" | - |
Affected
|