{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/opnsense--24.1.7/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:opnsense:opnsense:*:*:*:*:*:*:*:*"],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["OPNsense (\u003c 24.1.7)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["OPNsense"],"content_html":"\u003cp\u003eA security vulnerability has been identified in OPNsense, a popular open-source firewall and routing platform. The issue allows a remote attacker who has already obtained authenticated access to the system to perform a privilege escalation attack. By exploiting this flaw, an authenticated user could potentially gain administrative control over the firewall appliance, leading to unauthorized configuration changes, access to sensitive internal network traffic, or complete compromise of the security boundary. This vulnerability is tracked as CVE-2024-33235 and affects OPNsense versions prior to 24.1.7. Defenders are advised to review the administrative access logs and verify that all OPNsense instances are patched to the latest version to prevent unauthorized escalation by already authenticated users.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability permits an attacker with low-privileged access to achieve administrative rights. This impact extends to the entire security appliance, potentially exposing the protected network to exfiltration, unauthorized traffic interception, or the permanent disabling of security services managed by the OPNsense firewall.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all OPNsense instances to version 24.1.7 or later to resolve CVE-2024-33235.\u003c/li\u003e\n\u003cli\u003eAudit existing administrative user accounts and revoke access for any unauthorized or dormant accounts that could be used as an initial foothold for this escalation.\u003c/li\u003e\n\u003cli\u003eMonitor administrative login and configuration change logs for anomalous activity originating from non-administrative service accounts or standard user sessions.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-09T18:50:31Z","date_published":"2026-09-09T18:50:31Z","id":"https://feed.craftedsignal.io/briefs/2026-09-opnsense-priv-esc/","summary":"A vulnerability in OPNsense allows a remote, authenticated attacker to escalate their privileges, potentially gaining unauthorized administrative control over the firewall appliance.","title":"Privilege Escalation Vulnerability in OPNsense","url":"https://feed.craftedsignal.io/briefs/2026-09-opnsense-priv-esc/"}],"language":"en","title":"CraftedSignal Threat Feed - OPNsense (\u003c 24.1.7)","version":"https://jsonfeed.org/version/1.1"}