CVE-2022-31789: Buffer Overflow
An integer overflow in WatchGuard Firebox and XTM appliances allows an unauthenticated remote attacker to trigger a buffer overflow and potentially execute arbitrary code by sending a malicious request to exposed management ports. This is fixed in Fireware OS 12.8.1, 12.5.10, and 12.1.4.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-31789?
CVE-2022-31789 is an integer overflow vulnerability in WatchGuard Firebox and XTM appliances that allows an unauthenticated remote attacker to trigger a buffer overflow and potentially execute arbitrary code.
How can an attacker exploit CVE-2022-31789?
An attacker can exploit CVE-2022-31789 by sending a malicious request to exposed management ports of WatchGuard Firebox and XTM appliances.
What is the severity of CVE-2022-31789?
CVE-2022-31789 has a severity value of 9.8 (critical).
Which versions of WatchGuard Fireware are affected by CVE-2022-31789?
The affected versions of WatchGuard Fireware include 12.0.0 to 12.1.4, 12.2.0 to 12.5.10, 12.6.1-u1, 12.6.1-u3, 12.6.3, 12.6.4, 12.7.0-u1, 12.7.1, 12.7.2-u2, and 12.8.0-u1.
How can I fix CVE-2022-31789?
To fix CVE-2022-31789, you should update your WatchGuard Firebox or XTM appliance to Fireware OS 12.8.1, 12.5.10, or 12.1.4.