First published: Tue Sep 06 2022(Updated: )
WatchGuard Firebox and XTM appliances allow an unauthenticated remote attacker to retrieve sensitive authentication server settings by sending a malicious request to exposed authentication endpoints. This is fixed in Fireware OS 12.8.1, 12.5.10, and 12.1.4.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WatchGuard Fireware | >=12.0.0<12.1.4 | |
WatchGuard Fireware | >=12.2.0<12.5.10 | |
WatchGuard Fireware | =12.6.1-u1 | |
WatchGuard Fireware | =12.6.1-u3 | |
WatchGuard Fireware | =12.6.3 | |
WatchGuard Fireware | =12.6.4 | |
WatchGuard Fireware | =12.7.0-u1 | |
WatchGuard Fireware | =12.7.1 | |
WatchGuard Fireware | =12.7.2-u2 | |
WatchGuard Fireware | =12.8.0-u1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-31790.
The severity of CVE-2022-31790 is high.
WatchGuard Firebox and XTM appliances running Fireware versions between 12.0.0 and 12.8.0-u1 are affected by CVE-2022-31790.
An unauthenticated remote attacker can exploit CVE-2022-31790 by sending a malicious request to exposed authentication endpoints in WatchGuard Firebox and XTM appliances.
Yes, CVE-2022-31790 has been fixed in Fireware OS versions 12.8.1, 12.5.10, and 12.1.4.