First published: Wed Sep 20 2017(Updated: )
An FBX-5312 issue was discovered in WatchGuard Fireware before 12.0. If a login attempt is made in the XML-RPC interface with an XML message containing an empty member element, the wgagent crashes, logging out any user with a session opened in the UI. By continuously executing the failed login attempts, UI management of the device becomes impossible.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WatchGuard Fireware OS | <=11.12.4 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-14616 has a severity rating that indicates it can result in denial of service due to wgagent crashes.
To fix CVE-2017-14616, update WatchGuard Fireware to version 12.0 or later.
CVE-2017-14616 affects WatchGuard Fireware versions prior to 12.0.
CVE-2017-14616 enables denial of service attacks through a faulty XML-RPC login attempt.
Yes, exploiting CVE-2017-14616 can log out any user with an active session in the UI.