CVE Database
/

CVE-2022-24299

Back to search

CVE-2022-24299

Published: Mar 31, 2022

Modified: Aug 3, 2024

PUBLISHED

Description

Improper input validation vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software versions prior to 22.01) allows a remote attacker with the privilege to change OpenVPN client or server settings to execute an arbitrary command.

VendorProductVersions

pfSense

pfSense CE and pfSense Plus

affected
pfSense CE software versions prior to 2.6.0 and pfSense Plus software versions prior to 22.01

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now