CVE Database
/

CVE-2022-26019

Back to search

CVE-2022-26019

Published: Mar 31, 2022

Modified: Aug 3, 2024

PUBLISHED

Description

Improper access control vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software versions prior to 22.01) allows a remote attacker with the privilege to change NTP GPS settings to rewrite existing files on the file system, which may result in arbitrary command execution.

VendorProductVersions

pfSense

pfSense CE and pfSense Plus

affected
pfSense CE software versions prior to 2.6.0 and pfSense Plus software versions prior to 22.01

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now