Security Advisory

CVE-2022-24299

8.8
HIGH

Vulnerability Description

Improper input validation vulnerability in pfSense CE and pfSense Plus (pfSense CE software versions prior to 2.6.0 and pfSense Plus software versions prior to 22.01) allows a remote attacker with the privilege to change OpenVPN client or server settings to execute an arbitrary command.
Published Date March 31, 2022
Official Source NIST NVD Advisory