First published: Sat Apr 22 2017(Updated: )
WatchGuard Fireware allows user enumeration, e.g., in the Firebox XML-RPC login handler. A login request that contains a blank password sent to the XML-RPC agent in Fireware v11.12.1 and earlier returns different responses for valid and invalid usernames. An attacker could exploit this vulnerability to enumerate valid usernames on an affected Firebox.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WatchGuard Fireware OS | <=11.2.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2017-8055 has a medium severity rating due to the potential for user enumeration vulnerabilities.
To fix CVE-2017-8055, upgrade WatchGuard Fireware to version 11.12.2 or later.
CVE-2017-8055 affects WatchGuard Fireware versions up to and including 11.12.1.
CVE-2017-8055 is a user enumeration vulnerability in the Firebox XML-RPC login handler.
Yes, an attacker can exploit CVE-2017-8055 remotely by sending a login request with a blank password.