module

pfSense plugin pfBlockerNG unauthenticated RCE as root

Disclosed
Sep 5, 2022

Description

pfBlockerNG is a popular pfSense plugin that is not installed by default. It's generally used to
block inbound connections from whole countries or IP ranges. Versions 2.1.4_26 and below are affected
by an unauthenticated RCE vulnerability that results in root access. Note that version 3.x is unaffected.
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.