Vulnerability record · CVE-2023-27253 · published 17 March 2023
CVE-2023-27253: pfSense restore_rrddata() command injection via crafted XML config
Netgate · Pfsense
Netgate pfSense 2.7.0 contains a command injection flaw in the restore_rrddata() function. An authenticated attacker can supply a crafted XML file to the config.xml restore component and cause arbitrary commands to run on the firewall. Because pfSense is a perimeter device, successful exploitation can compromise network security controls.
Description
A command injection vulnerability in the function restore_rrddata() of Netgate pfSense v2.7.0 allows authenticated attackers to execute arbitrary commands via manipulating the contents of an XML file supplied to the component config.xml.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 8.8 with high EPSS and a public advisory make this a serious authenticated command injection on a perimeter firewall, though it requires valid credentials and is not in KEV.
What it is
Netgate pfSense 2.7.0 contains a command injection flaw in the restore_rrddata() function. An authenticated attacker can supply a crafted XML file to the config.xml restore component and cause arbitrary commands to run on the firewall. Because pfSense is a perimeter device, successful exploitation can compromise network security controls.
Impact
An attacker with a valid account gains arbitrary command execution on the pfSense appliance, with high impact to confidentiality, integrity and availability. This can lead to full device compromise and potential lateral movement into protected networks.
Attack surface
Reached over the network through the config.xml restore functionality, per the CVSS vector AV:N. The attacker must be authenticated with low privileges (PR:L); no user interaction is required (UI:N).
Exploitation
The record shows no CISA KEV listing and no ransomware association, but EPSS is very high at 0.895 (99.8th percentile), indicating elevated likelihood of exploitation activity. References include a public Packet Storm advisory and vendor patch, but no explicit proof-of-concept tag is present.
What to do
- Upgrade pfSense to a version containing the fix referenced in commit ca80d18493f8f91b21933ebd6b714215ae1e5e94.
- Restrict access to the pfSense webGUI and config restore functionality to trusted management networks only.
- Apply least privilege to pfSense accounts and remove or disable unused accounts that could reach the restore feature.
- Monitor and validate any XML configuration files restored to the appliance before import.
- Review vendor advisory redmine.pfsense.org/issues/13935 for any additional hardening guidance.
Detection
- Alert on unexpected child processes spawned by the pfSense webGUI or config restore components.
- Monitor pfSense audit and system logs for config.xml restore or RRD data restore actions outside change windows.
- Inspect uploaded XML files for shell metacharacters or unexpected command strings before restore.
- Watch for outbound connections or new processes on the firewall that do not match normal appliance behavior.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2023-27253 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-27253), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.