PoC Index

CVE-2023-27100

CRITICAL 9.8EPSS 9.8%

Improper restriction of excessive authentication attempts in the SSHGuard component of Netgate pfSense Plus software v22.05.1 and pfSense CE software v2.6.0 allows attackers to bypass brute force protection mechanisms via crafted web requests.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
9.84% chance of exploitation in the next 30 days, 95th percentile
Published
2023-03-22
Updated
2025-02-25

Proof-of-concept exploits (1)

ExploitDB entries (1)

References

Related