Vulnerability Details CVE-2014-4688
pfSense before 2.1.4 allows remote authenticated users to execute arbitrary commands via (1) the hostname value to diag_dns.php in a Create Alias action, (2) the smartmonemail value to diag_smart.php, or (3) the database value to status_rrd_graph_img.php.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.011
EPSS Ranking 77.3%
CVSS Severity
CVSS v2 Score 6.5
Products affected by CVE-2014-4688
-
cpe:2.3:a:netgate:pfsense:2.0
-
cpe:2.3:a:netgate:pfsense:2.0.1
-
cpe:2.3:a:netgate:pfsense:2.0.2
-
cpe:2.3:a:netgate:pfsense:2.0.3
-
cpe:2.3:a:netgate:pfsense:2.1.0
-
cpe:2.3:a:netgate:pfsense:2.1.1
-
cpe:2.3:a:netgate:pfsense:2.1.2
-
cpe:2.3:a:netgate:pfsense:2.1.3