CVE-2023-39004: Insecure permissions in the configuration directory (/conf/) of OPNsense Community Edition before 23.7 and...
Insecure permissions in the configuration directory (/conf/) of OPNsense Community Edition before 23.7 and Business Edition before 23.4.2 allow attackers to access sensitive information (e.g., hashed root password) which could lead to privilege escalation.
Security readout for executives and security teams
Plain-English summary
Affected OPNsense firewall installations may expose sensitive configuration data from the /conf/ directory, including a hashed root password. If an attacker can access that directory, the information could support privilege escalation. The public record does not provide CVSS scoring or a confirmed attack path.
Executive priority
Prioritize remediation on internet-facing or business-critical OPNsense firewalls. The issue affects security infrastructure and may expose root credential material, but current public evidence does not confirm active exploitation or a remote unauthenticated attack path.
Technical view
CVE-2023-39004 is an insecure-permissions issue in OPNsense Community Edition before 23.7 and Business Edition before 23.4.2. The issue concerns /conf/ directory permissions allowing sensitive information disclosure, with possible privilege escalation. Published sources do not state active exploitation or detailed prerequisite access.
Likely exposure
Exposure is limited to OPNsense Community Edition before 23.7 and Business Edition before 23.4.2. The source bundle does not define whether exploitation is local, remote, authenticated, or dependent on other access.
Exploitation context
CISA KEV is false in the provided bundle, and no cited source confirms active exploitation. The risk depends on whether an attacker can reach or read the affected configuration directory on a vulnerable OPNsense system.
Researcher notes
The CVE record lacks CVSS, CWE, and precise affected CPE data in the provided bundle. Avoid assuming broader pfSense, FreeBSD, or other firewall exposure. Focus validation on the named OPNsense editions and version thresholds.
Mitigation direction
Upgrade OPNsense Community Edition to 23.7 or later.
Upgrade OPNsense Business Edition to 23.4.2 or later.
Check OPNsense vendor guidance for permission or hardening instructions.
Rotate privileged credentials if configuration access may have occurred.
Validation and detection
Inventory OPNsense editions and versions across firewall assets.
Confirm no systems run Community Edition before 23.7.
Confirm no systems run Business Edition before 23.4.2.
Review local access and administrative access records for suspicious activity.
Compare /conf/ permissions with vendor-supported updated systems.
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Potential ATT&CK relevance
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
description · low confidence lookup
Credential and access behavior lookup
The CVE wording references authentication or credential exposure, so valid-account and credential-access review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
The CVE wording references privilege impact, so privilege escalation and authorization behavior review may help. This is a Glexia inferred lookup path, not an official MITRE, ATT&CK, or CVE Program mapping.
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
0CVSS vectors
3Timeline events
2ADP providers
2Source links
SSVC decision data
CISA-ADPCISA Coordinator
Timestamp
Version
2.0.3
Exploitation: pocAutomatable: yesTechnical Impact: total
Vulnerability timeline
Timeline events are normalized from CVE metadata, CNA source timelines, ADP timelines, and KEV metadata when present.
CVE reservedCVE Program
The CVE ID was reserved by the assigning CNA.
CVE publishedCVE Program
The CVE record was published.
Aug 9, 2023, 00:00 UTC (UTC+00:00)
CVE updatedCVE Program
The CVE record metadata indicates this as the latest update time.