Skip to content
VulniPulse

Netgate pfSense pfSense CE Vulnerabilities & Security Advisories

28 advisories tracked · Netgate Security Advisories + NVD · 0 listed in the CISA Known Exploited Vulnerabilities catalog

Every row below is a published Netgate pfSense advisory that VulniPulse classified as pfSense CE, with the CVEs, affected and fixed releases and exploitation status the vendor stated. Severity mix: 4 critical, 5 high, 19 medium.

Android app · Google Play

Monitor pfSense CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Source

Netgate Security Advisories + NVD

Netgate maintains a dedicated Security Advisory index for pfSense (docs.netgate.com/advisories), but pfSense CVEs are assigned by MITRE and third-party researchers rather than a Netgate CNA — so VulniPulse ingests them from NVD (keyword-filtered to pfSense, dropped unless a pfSense/Netgate product is named) and links back to the Netgate advisory or pfSense reference. Covers pfSense CE (Community Edition) and pfSense Plus — a firewall/router at the network edge where a bug is directly internet-exposed.

Latest pfSense pfSense CE advisories

High8.8pfSense

High [CVE-2023-48123] issue in Netgate pfSense Plus v.23.05.1 and before and pfSense CE v.2.7.0 allows a remote attacker to execute arbitrary code

An issue in Netgate pfSense Plus v.23.05.1 and before and pfSense CE v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the packet_capture.php file.

CVE-2023-48123
pfSense PluspfSense CE
Dec 6, 2023
High7.2pfSense

High [CVE-2023-29975] issue discovered in Pfsense CE version 2.6.0 allows attackers to change the password of any user without verification

An issue discovered in Pfsense CE version 2.6.0 allows attackers to change the password of any user without verification.

CVE-2023-29975
pfSense CE
Nov 9, 2023
Critical9.8pfSense

Critical [CVE-2023-29974] issue discovered in Pfsense CE version 2.6.0 allows attackers to compromise user accounts via weak password requirements

An issue discovered in Pfsense CE version 2.6.0 allows attackers to compromise user accounts via weak password requirements.

CVE-2023-29974
pfSense CE
Nov 8, 2023
Critical9.8pfSense

Critical [CVE-2023-27100] Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1…

Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE software v2.6.0 allows attackers to bypass brute force protection mechanisms via crafted web requests.

CVE-2023-27100
pfSense PluspfSense CE
Mar 22, 2023
High8.8pfSense

High [CVE-2022-26019] Improper access control vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense…

Improper access control vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software versions prior to 22.01) allows a remote attacker with the privilege to change NTP GPS settings to rewrite existing files on the file system, which may result in arbitrary command execution.

CVE-2022-26019
pfSense PluspfSense CE
Mar 31, 2022
High8.8pfSense

High [CVE-2022-24299] Improper input validation vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense…

Improper input validation vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software versions prior to 22.01) allows a remote attacker with the privilege to change OpenVPN client or server settings to execute an arbitrary command.

CVE-2022-24299
pfSense PluspfSense CE
Mar 31, 2022
Medium6.1pfSense

Medium [CVE-2021-20729] Cross-site scripting vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions 2.5.2 and earlier, and pfSense…

Cross-site scripting vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions 2.5.2 and earlier, and pfSense Plus software versions 21.05 and earlier) allows a remote attacker to inject an arbitrary script via a malicious URL.

CVE-2021-20729
pfSense PluspfSense CE
Mar 31, 2022
Medium6.1pfSense

Medium [CVE-2022-23993] /usr/local/www/pkg.php in pfSense CE before 2.6.0 and pfSense Plus before 22.01 uses $_REQUEST['pkg_filter'] in a PHP echo call

/usr/local/www/pkg.php in pfSense CE before 2.6.0 and pfSense Plus before 22.01 uses $_REQUEST['pkg_filter'] in a PHP echo call, causing XSS.

CVE-2022-23993
pfSense PluspfSense CE
Jan 26, 2022

← All pfSense advisories