Cyber Resilience

CVE-2023-48123

Netgate Pfsense ≤ 2.7.0

High EPSS
Published
06 December 2023
Modified
21 November 2024
Patch / advisory
CVSS Score v3.1 8.8
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.68 99.3th percentile
Risk Priority 89 floored blend · peak EPSS

Summary

CVE-2023-48123 is a high-severity an unspecified weakness vulnerability in Netgate Pfsense. Its CVSS base score is 8.8 (High).

Operationally, ranked in the top 0.7% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.

Deeper analysis AI-assisted summary

Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.

CVE-2023-48123 is an arbitrary code execution vulnerability in the web interface of Netgate pfSense Plus versions 23.05.1 and earlier as well as pfSense CE 2.7.0. The flaw resides in packet_capture.php and can be triggered by sending a specially crafted request to that endpoint.

An authenticated remote attacker with low privileges can exploit the issue over the network without user interaction, achieving full code execution that yields high impacts on confidentiality, integrity, and availability.

Netgate published advisory pfSense-SA-23_11.webgui and a corresponding code commit that addresses the flaw; administrators are advised to apply the update or the referenced patch.

The EPSS score has remained at 0.6825 since disclosure with no material upward movement.

EU & UK References

Vulnerability Data

An issue in Netgate pfSense Plus v.23.05.1 and before and pfSense CE v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the packet_capture.php file.

CWE(s)

Related Threats

CVEs Like This One

CVE-2023-42326Same product: Netgate Pfsense
CVE-2019-16667Same product: Netgate Pfsense
CVE-2023-42325Same product: Netgate Pfsense
CVE-2023-27253Same product: Netgate Pfsense
CVE-2023-42327Same product: Netgate Pfsense
CVE-2024-46538Same product: Netgate Pfsense
CVE-2024-54780Same product: Netgate Pfsense Plus
CVE-2024-57273Same product: Netgate Pfsense Plus
CVE-2024-54779Same product: Netgate Pfsense Plus
CVE-2022-31814Same vendor: Netgate

Affected Assets

netgate
pfsense
≤ 2.7.0
netgate
pfsense plus
≤ 23.05.1

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References