pfSense pfBlockerNG 2.1.4_26 is vulnerable to a command injection.

ISGroup Cybersecurity

Executive Summary

A critical vulnerability has been discovered in the pfBlockerNG 2.1.4_26 module for pfSense, which allows a remote attacker to execute commands as the root user. This occurs due to insecure handling of special characters in the HTTP Host header. Since the vulnerability is being actively exploited, an immediate update is recommended.

ProductpfSense
Date2024-08-15 10:27:26

Technical Summary

pfSense pfBlockerNG 2.1.4_26 is vulnerable to remote command execution as root due to improper handling of shell metacharacters in the HTTP Host header. Exploitation of this vulnerability is straightforward and allows attackers to gain full control of the server and its data. Considering that this flaw is being actively exploited, it is critical to update to a secure version of pfBlockerNG immediately.

Protect your organisation with Threat Intelligence and Digital Risk Protection.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert