V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2023-27100
CVE
CriticalConfirmedExploit available

Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense C…

CVSS
9.8
Critical
EPSS
0.03
p86
Published
2023-01-01
Updated
2023-01-01
Description

Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE software v2.6.0 allows attackers to bypass brute force protection mechanisms via crafted web requests.

Tags · CWE
Pre-auth
CWE-307
CAPEC-16
CAPEC-49
CAPEC-560
CAPEC-565
CAPEC-600
CAPEC-652
CAPEC-653
Affected products
Pfsense_plusPfsense
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
2023-01-01
Published
2023-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.030 · p86
Known exploited (KEV)
No
MITRE ATT&CK
Inferred via CAPEC
└ via CAPEC-560 · CWE-307
└ via CAPEC-49 · CWE-307
└ via CAPEC-565 · CWE-307
└ via CAPEC-600 · CWE-307
└ via CAPEC-652 · CWE-307
Known exploits — Сканер-ВС
51352
exploitdb · https://www.exploit-db.com/exploits/51352
Enterprise
CVE-2023-27100
github-poc · https://github.com/fabdotnet/CVE-2023-27100
Enterprise
Affected software
ProductVendorStatus
pfsense*Tracked
pfsense_plus*Tracked
Source databases
CVE