CVE Wiki Pixee · CVE intelligence
← All CVEs

CVE-2023-39004

Critical · CVSS 9.8

OPNsense — Insecure file/directory permissions leading to sensitive information disclosure and privilege escalation (CWE-732)

CVSS
9.8
nvd
EPSS
KEV
No
Class
oss containerizable
CWE-732

Description

Insecure permissions in the configuration directory (/conf/) of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allow attackers to access sensitive information (e.g., hashed root password) which could lead to privilege escalation.

Search profile — drives PoC discovery

Symbols /conf/config.xmlhashed root password/conf/config.xmlconfiguration directoryinsecure permissions
Keywords CVE-2023-39004OPNsense insecure permissionsOPNsense /conf/ directoryOPNsense privilege escalationOPNsense hashed root passwordOPNsense sensitive information disclosureOPNsense Community Edition 23.7OPNsense Business Edition 23.4.2OPNsense CWE-732logicaltrust opnsense
Versions: Community Edition < 23.7; Business Edition < 23.4.2

Ranked PoCs (1) — best first

Heuristic ranking — not yet expert-vetted. Scored on structure + provenance, not execution.

Recall-favoring discovery; ranking by the Stage-4 scorer (Adam's rubric). Scanner/aggregator repos are hidden.

References

Status: enriched · ingested 2026-07-05T06:00:39.000Z · profiled 2026-07-05T18:30:39.000Z