CVE-2022-25292: Buffer Overflow
A wgagent stack-based buffer overflow in WatchGuard Firebox and XTM appliances allows an authenticated remote attacker to potentially execute arbitrary code by initiating a firmware update with a malicious upgrade image. This vulnerability impacts Fireware OS before 12.7.2U2, 12.x before 12.1.3U8, and 12.2.x through 12.5.x before 12.5.9U2.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-25292?
CVE-2022-25292 is a vulnerability in WatchGuard Firebox and XTM appliances that allows an authenticated remote attacker to potentially execute arbitrary code by initiating a firmware update with a malicious upgrade image.
Which software versions are affected by CVE-2022-25292?
CVE-2022-25292 impacts Fireware OS versions before 12.7.2_U2, 12.x before 12.1.3_U8, and 12.1.3-u1 through 12.1.3-u7, 12.5.9 and 12.5.9-u1, and 12.7.0 through 12.7.2-u1.
What is the severity of CVE-2022-25292?
CVE-2022-25292 has a severity score of 8.8 (high).
How can the CVE-2022-25292 vulnerability be fixed?
To fix the CVE-2022-25292 vulnerability, users should update their Fireware OS to version 12.7.2_U2 or later.
Where can I find more information about CVE-2022-25292?
More information about CVE-2022-25292 can be found at the MITRE CWE database and the WatchGuard Fireware release notes.