DECISO OPNsense 23.1 does not impose rate limits for authentication, allowing attackers to perform a brute-force attack to bypass authentication.
References
Link | Resource |
---|---|
https://www.esecforte.com/cve-2023-27152-opnsense-brute-force/ | Exploit Third Party Advisory |
https://www.esecforte.com/cve-2023-27152-opnsense-brute-force/ | Exploit Third Party Advisory |
Configurations
History
No history.
Information
Published : 2023-10-23 21:15
Updated : 2024-11-21 07:52
NVD link : CVE-2023-27152
Mitre link : CVE-2023-27152
CVE.ORG link : CVE-2023-27152
JSON object : View
Products Affected
opnsense
- opnsense
CWE
CWE-307
Improper Restriction of Excessive Authentication Attempts