CVE-2017-14616: High severity watchguard fireware os vulnerability
An FBX-5312 issue was discovered in WatchGuard Fireware before 12.0. If a login attempt is made in the XML-RPC interface with an XML message containing an empty member element, the wgagent crashes, logging out any user with a session opened in the UI. By continuously executing the failed login attempts, UI management of the device becomes impossible.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-14616?
CVE-2017-14616 has a severity rating that indicates it can result in denial of service due to wgagent crashes.
How do I fix CVE-2017-14616?
To fix CVE-2017-14616, update WatchGuard Fireware to version 12.0 or later.
What does CVE-2017-14616 affect?
CVE-2017-14616 affects WatchGuard Fireware versions prior to 12.0.
What type of attack does CVE-2017-14616 enable?
CVE-2017-14616 enables denial of service attacks through a faulty XML-RPC login attempt.
Can I be logged out due to CVE-2017-14616?
Yes, exploiting CVE-2017-14616 can log out any user with an active session in the UI.