Pfsense

Vendor:

First CVE: Jul 2, 2014 · Active for 12 years

49
Total CVEs
More Total CVEs than 98% of tracked products
5.4
Avg CVEs / Year
Higher CVE frequency than 89% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 31% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Pfsense over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jul 2, 2014
12 years ago
Most Recent CVE
Oct 22, 2024
640 days ago

CVE Severity & Scoring

Pfsense49 CVEs
All CVEs352,294 CVEs
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network31 (63.3%)
Unknown18 (36.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low31 (63.3%)
High0 (0.0%)
Unknown18 (36.7%)
User Interaction
None15 (30.6%)
Unknown18 (36.7%)
Required16 (32.7%)
Privileges Required
Low12 (24.5%)
High5 (10.2%)
None14 (28.6%)
Unknown18 (36.7%)

Top CVEs

Signals from CVEs in this product scope (49 CVEs).

49 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attackers to execute arbitrary commands via manipulating the cont
Mar 17, 20238.884NOYES
diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executing OS commands. This occurs because csrf_callback() produces
Sep 26, 20198.869NOYES
An issue in Netgate pfSense v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the interfaces_gif_edit.php and interfaces_gre_edit.php components.
Nov 14, 20238.864NONO
In pfSense 2.4.4-p3, a stored XSS vulnerability occurs when attackers inject a payload into the Name or Description field via an acme_accountkeys_edit.php action. The vulnerability
May 29, 20196.164NOYES
An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POST request. The attacker can exploit this
Dec 3, 20187.263NONO
Cross-site request forgery (CSRF) vulnerability in system_firmware_restorefullbackup.php in the WebGUI in pfSense before 2.2.1 allows remote attackers to hijack the authentication
Apr 10, 20156.863NOYES
A cross-site scripting (XSS) vulnerability in pfsense v2.5.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the $pconfig variable at
Oct 22, 20244.862NONO
An issue in Netgate pfSense Plus v.23.05.1 and before and pfSense CE v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the packet_capture.php file
Dec 6, 20238.858NONO
pfSense versions 2.4.1 and lower are vulnerable to clickjacking attacks in the CSRF error page resulting in privileged execution of arbitrary code, because the error detection occu
Jan 3, 20188.855NOYES
pfSense CE through 2.6.0 and pfSense Plus before 22.05 allow XSS in the WebGUI via URL Table Alias URL parameters.
Feb 22, 20236.152NONO

Exploit Exposure

Signals from CVEs in this product scope (49 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
4.1% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
7 CVEs
14.3% of CVEs· 89th percentile

Social Chatter

Signals from CVEs in this product scope (49 CVEs).

Media Mentions

Signals from CVEs in this product scope (49 CVEs).

Top CNAs Publishing CVEs For Pfsense

Top CWEs

Versions

VersionCVE CountAvg CVSSAvg EPSSKEVExploits
2.7.036.567.6%01
2.5.214.877.9%00
2.4.4187.511.6%03
2.2.117.84.2%00
2.1.345.01.9%00