First published: Tue Sep 06 2022(Updated: )
An integer overflow in WatchGuard Firebox and XTM appliances allows an unauthenticated remote attacker to trigger a buffer overflow and potentially execute arbitrary code by sending a malicious request to exposed management ports. This is fixed in Fireware OS 12.8.1, 12.5.10, and 12.1.4.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WatchGuard Fireware | >=12.0.0<12.1.4 | |
WatchGuard Fireware | >=12.2.0<12.5.10 | |
WatchGuard Fireware | =12.6.1-u1 | |
WatchGuard Fireware | =12.6.1-u3 | |
WatchGuard Fireware | =12.6.3 | |
WatchGuard Fireware | =12.6.4 | |
WatchGuard Fireware | =12.7.0-u1 | |
WatchGuard Fireware | =12.7.1 | |
WatchGuard Fireware | =12.7.2-u2 | |
WatchGuard Fireware | =12.8.0-u1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-31789 is an integer overflow vulnerability in WatchGuard Firebox and XTM appliances that allows an unauthenticated remote attacker to trigger a buffer overflow and potentially execute arbitrary code.
An attacker can exploit CVE-2022-31789 by sending a malicious request to exposed management ports of WatchGuard Firebox and XTM appliances.
CVE-2022-31789 has a severity value of 9.8 (critical).
The affected versions of WatchGuard Fireware include 12.0.0 to 12.1.4, 12.2.0 to 12.5.10, 12.6.1-u1, 12.6.1-u3, 12.6.3, 12.6.4, 12.7.0-u1, 12.7.1, 12.7.2-u2, and 12.8.0-u1.
To fix CVE-2022-31789, you should update your WatchGuard Firebox or XTM appliance to Fireware OS 12.8.1, 12.5.10, or 12.1.4.