CVE-2022-25291: Buffer Overflow
An integer overflow in WatchGuard Firebox and XTM appliances allows an authenticated remote attacker to trigger a heap-based buffer overflow and potentially execute arbitrary code by initiating a firmware update with a malicious upgrade image. This vulnerability impacts Fireware OS before 12.7.2U2, 12.x before 12.1.3U8, and 12.2.x through 12.5.x before 12.5.9U2.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-25291?
CVE-2022-25291 is a vulnerability in WatchGuard Firebox and XTM appliances that allows an authenticated remote attacker to trigger a heap-based buffer overflow and potentially execute arbitrary code by initiating a firmware update with a malicious upgrade image.
Which software versions are affected by CVE-2022-25291?
CVE-2022-25291 affects Fireware OS versions before 12.7.2_U2, 12.1.3 - 12.5.9, and 12.7.0 - 12.7.2.
How severe is CVE-2022-25291?
CVE-2022-25291 has a severity rating of 8.8 (high).
How can I fix CVE-2022-25291?
To fix CVE-2022-25291, users should update their Fireware OS to version 12.7.2_U2 or later.
Where can I find more information about CVE-2022-25291?
More information about CVE-2022-25291 can be found at the following link: [CVE-2022-25291](https://www.watchguard.com/support/release-notes/fireware/12/en-US/EN_ReleaseNotes_Fireware_12_7_2/index.html#Fireware/en-US/resolved_issues.html)