Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
In pfSense 2.4.4_1, blocking of source IP addresses on the basis of failed HTTPS authentication is inconsistent with blocking of source IP addresses on the basis of failed SSH authentication (the behavior does not match the sshguard documentation), which might make it easier for attackers to bypass intended access restrictions.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
pfSense 权限许可和访问控制问题漏洞
Vulnerability Description
pfSense是一套基于FreeBSD Linux的网络防火墙。 pfSense 2.4.4_1版本中存在安全漏洞,该漏洞源于程序根据SSH身份验证失败的情况和HTTPS身份验证失败的情况来封锁源IP地址,但两者并不相符。攻击者可利用该漏洞绕过访问限制。
CVSS Information
N/A
Vulnerability Type
N/A