Packetfence is a network access control platform deployed in enterprise environments to manage device authentication and authorization, with its vulnerability profile centered on a single product. The observed exposure recurs through authentication bypass pathways, web-input handling issues such as cross-site scripting, and directory-service injection vulnerabilities including LDAP injection, reflecting the authentication and identity-integration demands of a network-gating appliance. Live severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Packetfence over time
Signals from CVEs in this vendor scope (5 CVEs).
5 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2011-4069CRITICAL html/admin/login.php in PacketFence before 3.0.2 allows remote attackers to conduct LDAP injection attacks and consequently bypass authentication via a crafted username. | Feb 1, 2018 | 9.8 | 30 | NO | NO |
CVE-2011-4068CRITICAL The check_password function in html/admin/login.php in PacketFence before 3.0.2 allows remote attackers to bypass authentication via an empty password. | Feb 1, 2018 | 9.8 | 30 | NO | NO |
CVE-2012-4742HIGH The web_node_register function in web.pm in PacketFence before 3.0.2 might allow remote attackers to execute arbitrary code via unspecified vectors. | Aug 31, 2012 | 7.5 | 23 | NO | NO |
CVE-2012-4741MEDIUM The RADIUS extension in PacketFence before 3.3.0 uses a different user name than is used for authentication for users with custom VLAN assignment extensions, which allows remote at | Aug 31, 2012 | 5.0 | 18 | NO | NO |
CVE-2012-4740MEDIUM Cross-site scripting (XSS) vulnerability in the captive portal in PacketFence before 3.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Aug 31, 2012 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (5 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Packetfence.
Media articles that mention a CVE ID that affects a product developed by Packetfence — matched by CVE ID, not by vendor name.