First published: Tue Jun 07 2022(Updated: )
WatchGuard Firebox and XTM appliances allow an unauthenticated remote attacker to delete arbitrary files from a limited set of directories on the system. This vulnerability impacts Fireware OS before 12.7.2_U2, 12.x before 12.1.3_U8, and 12.2.x through 12.5.x before 12.5.9_U2.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WatchGuard Fireware | >=12.0.0<12.1.3 | |
WatchGuard Fireware | >=12.2.0<12.5.9 | |
WatchGuard Fireware | =12.1.3 | |
WatchGuard Fireware | =12.1.3-u1 | |
WatchGuard Fireware | =12.1.3-u2 | |
WatchGuard Fireware | =12.1.3-u3 | |
WatchGuard Fireware | =12.1.3-u4 | |
WatchGuard Fireware | =12.1.3-u5 | |
WatchGuard Fireware | =12.1.3-u6 | |
WatchGuard Fireware | =12.1.3-u7 | |
WatchGuard Fireware | =12.5.9 | |
WatchGuard Fireware | =12.5.9-u1 | |
WatchGuard Fireware | =12.7.2 | |
WatchGuard Fireware | =12.7.2-u1 | |
Watchguard Firebox M200 | ||
Watchguard Firebox M270 | ||
Watchguard Firebox M290 | ||
Watchguard Firebox M300 | ||
Watchguard Firebox M370 | ||
Watchguard Firebox M390 | ||
Watchguard Firebox M400 | ||
Watchguard Firebox M440 | ||
Watchguard Firebox M470 | ||
Watchguard Firebox M4800 | ||
Watchguard Firebox M500 | ||
Watchguard Firebox M570 | ||
Watchguard Firebox M5800 | ||
Watchguard Firebox M590 | ||
Watchguard Firebox M670 | ||
Watchguard Firebox M690 | ||
Watchguard Firebox T10 | ||
Watchguard Firebox T10-d | ||
Watchguard Firebox T10-w | ||
Watchguard Firebox T15 | ||
Watchguard Firebox T15-w | ||
Watchguard Firebox T20 | ||
Watchguard Firebox T20-w | ||
Watchguard Firebox T30 | ||
Watchguard Firebox T30-w | ||
Watchguard Firebox T35 | ||
Watchguard Firebox T35-r | ||
Watchguard Firebox T35-w | ||
Watchguard Firebox T40 | ||
Watchguard Firebox T40-w | ||
Watchguard Firebox T50 | ||
Watchguard Firebox T50-w | ||
Watchguard Firebox T55 | ||
Watchguard Firebox T55-w | ||
Watchguard Firebox T70 | ||
Watchguard Firebox T80 | ||
Watchguard Firebox Xtm1520-rp | ||
Watchguard Firebox Xtm1525-rp | ||
Watchguard Firebox Xtm2520 | ||
Watchguard Firebox Xtm850 | ||
Watchguard Firebox Xtm860 | ||
Watchguard Firebox Xtm870 | ||
Watchguard Firebox Xtm870-f | ||
Watchguard Fireboxcloud | ||
Watchguard Fireboxv | ||
Watchguard Xtmv |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-25361 is a vulnerability that allows an unauthenticated remote attacker to delete arbitrary files from a limited set of directories on WatchGuard Firebox and XTM appliances.
Fireware OS versions before 12.7.2_U2, 12.x before 12.1.3_U8, and 12.2.x through 12.5.x before 12.5.9_U2 are affected by CVE-2022-25361.
CVE-2022-25361 has a severity score of 9.1, which is considered critical.
To fix CVE-2022-25361, update Fireware OS to version 12.7.2_U2, 12.x to version 12.1.3_U8, or 12.2.x through 12.5.x to version 12.5.9_U2.
You can find more information about CVE-2022-25361 on the WatchGuard website and the WatchGuard PSIRT advisory WGSa-2022-00004.