CVE Published: 31/03/2022 |
CVE Updated: 03/08/2024 |
CVE Year: 2022 Source: jpcert |
Vendor: pfSense |
Product: pfSense CE and pfSense Plus Status : PUBLISHED
CVE-2022-26019 Description
Improper access control vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software versions prior to 22.01) allows a remote attacker with the privilege to change NTP GPS settings to rewrite existing files on the file system, which may result in arbitrary command execution.