RULE(RULE ID:333262)

Rule General Information
Release Date: 2021-03-26
Rule Name: Electric Sheep Fencing pfSense system_groupmanager.php Command Injection Vulnerability
Severity:
CVE ID:
Rule Protection Details
Description: A command injection vulnerability has been reported in the web console of the Electric Sheep Fencing pfSense firewall. The vulnerability is due to a failure on part of the application to properly parse input supplied to the members parameter in the system_groupmanager.php script. A remote, authenticated attacker could exploit this vulnerability by sending crafted HTTP requests to the target server. Successful exploitation allows the attacker to execute arbitrary commands under the security context of ROOT.
Impact: An attacker can execute arbitrary command via a successful exploit in the context of the vulnerable software.
Affected OS: Windows, Linux, Others
Reference:
Solutions
Please contact the software vendor to update the software patch.