Multiple pfSense Firewall Vulnerabilities Let Attackers Inject Malicious Codes
Three critical vulnerabilities have been identified in pfSense firewall software, affecting both the Community Edition (CE) and pfSense Plus builds prior to version 2.8.0 beta. These vulnerabilities, CVE-2024-57273, CVE-2024-54780, and CVE-2024-54779,…
Three critical vulnerabilities have been identified in pfSense firewall software, affecting both the Community Edition (CE) and pfSense Plus builds prior to version 2.8.0 beta. These vulnerabilities, CVE-2024-57273, CVE-2024-54780, and CVE-2024-54779, could allow authenticated attackers to execute malicious actions, including code injection, manipulation of cloud backups, and potential remote code execution.
CVE-2024-57273: Affects the Automatic Configuration Backup (ACB) service. Enables the hijacking of cloud backup keys, leading to backup deletion, stored cross-site scripting (XSS) attacks, and information leakage. Exploitation requires an accessible SSH server and ACB configuration. CVE-2024-54780: Involves command injection in the OpenVPN widget. Allows attackers to inject arbitrary OpenVPN management commands via the unsanitized remipp parameter. CVE-2024-54779: Enables XML injection in dashboard widgets via the widgetkey parameter, potentially causing configuration file corruption and persistent XSS attacks.
The vulnerabilities stem from inadequate sanitization of inputs, allowing attackers to manipulate system configurations and execute unauthorized commands.
Netgate has addressed these vulnerabilities in the upcoming pfSense Plus 25.03 and CE 2.8.0 releases. Fixes for current versions, pfSense Plus 24.11 and CE 2.7.2, are available through the System Patches Package. Patches address issues such as:
CVE-2024-57273: Affects the Automatic Configuration Backup (ACB) service.
Multiple XSS vulnerabilities in Dashboard widgets. OpenVPN management interface command injection. XSS in AutoConfigBackup backup list. Potential disclosure of AutoConfigBackup Device Key. Stored XSS in various system components.
Security researchers reported these vulnerabilities to Netgate between November and December 2024, and patches are now available in the public pfSense 2.8.0 beta and GitHub master branch. The Exploit Prediction Scoring System (EPSS) rates the likelihood of exploitation for CVE-2024-54779 at 0.03%, but it is strongly recommended for administrators to apply patches immediately.
Users should update to pfSense CE version 2.8.0 or later, or the corresponding version of pfSense Plus. For those unable to update immediately, installing the System Patches Package provides temporary protection.
Based on reporting by Cyber Security News.
