← Back

CVE-2023-27100

nvd nist
Published: Mar 22, 2023Modified: Jun 17, 2026

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE software v2.6.0 allows attackers to bypass brute force protection mechanisms via crafted web requests.

Affected (2)

1 product
Pfsense Plus
1 product
Pfsense
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Version 22.05.1
Version 2.6.0

References (7)

Source: cve@mitre.org
Issue TrackingPatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingPatchVendor Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0

Timeline

No history available yet.