CVE-2022-31790: High severity watchguard fireware os vulnerability
Published Sep 6, 2022
·Updated
WatchGuard Firebox and XTM appliances allow an unauthenticated remote attacker to retrieve sensitive authentication server settings by sending a malicious request to exposed authentication endpoints. This is fixed in Fireware OS 12.8.1, 12.5.10, and 12.1.4.
Affected Software
10 affected components
WatchGuard Fireware>=12.0.0<12.1.4
WatchGuard Fireware>=12.2.0<12.5.10
WatchGuard Fireware=12.6.1-u1
WatchGuard Fireware=12.6.1-u3
WatchGuard Fireware=12.6.3
WatchGuard Fireware=12.6.4
WatchGuard Fireware=12.7.0-u1
WatchGuard Fireware=12.7.1
WatchGuard Fireware=12.7.2-u2
WatchGuard Fireware=12.8.0-u1
Event History
Sep 6, 2022
CVE Published
via MITRE·05:54 PM
Data Sourced
via MITRE·05:54 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-31790.
2
What is the severity of CVE-2022-31790?
The severity of CVE-2022-31790 is high.
3
Which software versions are affected by CVE-2022-31790?
WatchGuard Firebox and XTM appliances running Fireware versions between 12.0.0 and 12.8.0-u1 are affected by CVE-2022-31790.
4
How can an attacker exploit CVE-2022-31790?
An unauthenticated remote attacker can exploit CVE-2022-31790 by sending a malicious request to exposed authentication endpoints in WatchGuard Firebox and XTM appliances.
5
Has CVE-2022-31790 been fixed?
Yes, CVE-2022-31790 has been fixed in Fireware OS versions 12.8.1, 12.5.10, and 12.1.4.