CVE-2023-39004
09.08.2023, 19:15
Insecure permissions in the configuration directory (/conf/) of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allow attackers to access sensitive information (e.g., hashed root password) which could lead to privilege escalation.Enginsight
Vendor | Product | Version |
---|---|---|
opnsense | opnsense | 𝑥 < 23.7 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration