CVE-2023-38999
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2023-38999 is a newly disclosed Cross-Site Request Forgery (CSRF) vulnerability that affects OPNsense Community Edition versions prior to 23.7 and Business Edition versions prior to 23.4.2. This issue enables attackers to execute a Denial of Service (DoS) attack by sending a maliciously crafted GET request through the System Halt API (/system/halt). Successful exploitation of this vulnerability can result in disrupting the normal functioning of the OPNsense system, causing significant inconvenience and potential downtime for organizations. It is highly recommended that users upgrade their OPNsense installations to the latest versions as soon as possible to mitigate this threat.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- OPNsense
Affected Vendors
- Opnsense