Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-31814


pfSense pfBlockerNG through 2.1.4_26 allows remote attackers to execute arbitrary OS commands as root via shell metacharacters in the HTTP Host header. NOTE: 3.x is unaffected.


Published

2022-09-05T16:15:08.500

Last Modified

2024-11-21T07:05:22.740

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Primary
    CWE-78
  • Type: Secondary
    CWE-78

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application netgate pfblockerng ≤ 2.1.4_26 Yes

References