Pfsense
Vendor:
First CVE: Jul 2, 2014 · Active for 12 years
49
Total CVEs
More Total CVEs than 98% of tracked products
5.4
Avg CVEs / Year
Higher CVE frequency than 89% of tracked products
6.5
Avg CVSS
Higher Avg CVSS than 31% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Pfsense over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jul 2, 2014
12 years ago
Most Recent CVE
Oct 22, 2024
640 days ago
CVE Severity & Scoring
Pfsense49 CVEs
61%
33%
All CVEs352,294 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network31 (63.3%)
Unknown18 (36.7%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low31 (63.3%)
High0 (0.0%)
Unknown18 (36.7%)
User Interaction
None15 (30.6%)
Unknown18 (36.7%)
Required16 (32.7%)
Privileges Required
Low12 (24.5%)
High5 (10.2%)
None14 (28.6%)
Unknown18 (36.7%)
Top CVEs
Signals from CVEs in this product scope (49 CVEs).
49 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-27253HIGH A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attackers to execute arbitrary commands via manipulating the cont | Mar 17, 2023 | 8.8 | 84 | NO | YES |
CVE-2019-16667HIGH diag_command.php in pfSense 2.4.4-p3 allows CSRF via the txtCommand or txtRecallBuffer field, as demonstrated by executing OS commands. This occurs because csrf_callback() produces | Sep 26, 2019 | 8.8 | 69 | NO | YES |
CVE-2023-42326HIGH An issue in Netgate pfSense v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the interfaces_gif_edit.php and interfaces_gre_edit.php components. | Nov 14, 2023 | 8.8 | 64 | NO | NO |
CVE-2019-12347MEDIUM In pfSense 2.4.4-p3, a stored XSS vulnerability occurs when attackers inject a payload into the Name or Description field via an acme_accountkeys_edit.php action. The vulnerability | May 29, 2019 | 6.1 | 64 | NO | YES |
CVE-2018-4021HIGH An exploitable command injection vulnerability exists in the way Netgate pfSense CE 2.4.4-RELEASE processes the parameters of a specific POST request. The attacker can exploit this | Dec 3, 2018 | 7.2 | 63 | NO | NO |
CVE-2015-2295MEDIUM Cross-site request forgery (CSRF) vulnerability in system_firmware_restorefullbackup.php in the WebGUI in pfSense before 2.2.1 allows remote attackers to hijack the authentication | Apr 10, 2015 | 6.8 | 63 | NO | YES |
CVE-2024-46538MEDIUM A cross-site scripting (XSS) vulnerability in pfsense v2.5.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the $pconfig variable at | Oct 22, 2024 | 4.8 | 62 | NO | NO |
CVE-2023-48123HIGH An issue in Netgate pfSense Plus v.23.05.1 and before and pfSense CE v.2.7.0 allows a remote attacker to execute arbitrary code via a crafted request to the packet_capture.php file | Dec 6, 2023 | 8.8 | 58 | NO | NO |
CVE-2017-1000479HIGH pfSense versions 2.4.1 and lower are vulnerable to clickjacking attacks in the CSRF error page resulting in privileged execution of arbitrary code, because the error detection occu | Jan 3, 2018 | 8.8 | 55 | NO | YES |
CVE-2022-29273MEDIUM pfSense CE through 2.6.0 and pfSense Plus before 22.05 allow XSS in the WebGUI via URL Table Alias URL parameters. | Feb 22, 2023 | 6.1 | 52 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (49 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
2 CVEs
4.1% of CVEs· 96th percentile
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
7 CVEs
14.3% of CVEs· 89th percentile
Social Chatter
Signals from CVEs in this product scope (49 CVEs).
Media Mentions
Signals from CVEs in this product scope (49 CVEs).
Top CNAs Publishing CVEs For Pfsense
Top CWEs
Versions
| Version | CVE Count | Avg CVSS | Avg EPSS | KEV | Exploits |
|---|---|---|---|---|---|
| 2.7.0 | 3 | 6.5 | 67.6% | 0 | 1 |
| 2.5.2 | 1 | 4.8 | 77.9% | 0 | 0 |
| 2.4.4 | 18 | 7.5 | 11.6% | 0 | 3 |
| 2.2.1 | 1 | 7.8 | 4.2% | 0 | 0 |
| 2.1.3 | 4 | 5.0 | 1.9% | 0 | 0 |