CyberRota Analysis
This is a medium severity vulnerability with a CVSS score of 5.0. It may be remotely exploitable. Exploitation may require the attacker to be authenticated.
CVE
CVE-2014-4690
Severity
MEDIUM
CVSS
5
EPSS
3.50%
Original NVD Description
Multiple directory traversal vulnerabilities in pfSense before 2.1.4 allow (1) remote attackers to read arbitrary .info files via a crafted path in the pkg parameter to pkg_mgr_install.php and allow (2) remote authenticated users to read arbitrary files via the downloadbackup parameter to system_firmware_restorefullbackup.php.