CVE-2023-38999

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Aug 9, 2023
Updated: Oct 10, 2023
CWE ID 352

Summary

CVE-2023-38999 is a newly disclosed Cross-Site Request Forgery (CSRF) vulnerability that affects OPNsense Community Edition versions prior to 23.7 and Business Edition versions prior to 23.4.2. This issue enables attackers to execute a Denial of Service (DoS) attack by sending a maliciously crafted GET request through the System Halt API (/system/halt). Successful exploitation of this vulnerability can result in disrupting the normal functioning of the OPNsense system, causing significant inconvenience and potential downtime for organizations. It is highly recommended that users upgrade their OPNsense installations to the latest versions as soon as possible to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share