First published: Tue Sep 06 2022(Updated: )
WatchGuard Firebox and XTM appliances allow a local attacker (that has already obtained shell access) to elevate their privileges and execute code with root permissions. This is fixed in Fireware OS 12.8.1, 12.5.10, and 12.1.4.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
WatchGuard Fireware | >=12.0.0<12.1.4 | |
WatchGuard Fireware | >=12.2.0<12.5.10 | |
WatchGuard Fireware | =12.6.1-u1 | |
WatchGuard Fireware | =12.6.1-u3 | |
WatchGuard Fireware | =12.6.3 | |
WatchGuard Fireware | =12.6.4 | |
WatchGuard Fireware | =12.7.0-u1 | |
WatchGuard Fireware | =12.7.1 | |
WatchGuard Fireware | =12.7.2-u2 | |
WatchGuard Fireware | =12.8.0-u1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-31791 is a vulnerability in WatchGuard Firebox and XTM appliances that allows a local attacker with shell access to elevate their privileges and execute code with root permissions.
CVE-2022-31791 has a severity score of 7.8, which is considered high.
WatchGuard Fireware versions 12.0.0 to 12.1.4, 12.2.0 to 12.5.10, 12.6.1-u1, 12.6.1-u3, 12.6.3, 12.6.4, 12.7.0-u1, 12.7.1, 12.7.2-u2, and 12.8.0-u1 are affected by CVE-2022-31791.
You can fix CVE-2022-31791 by updating to Fireware OS versions 12.8.1, 12.5.10, or 12.1.4.
You can find more information about CVE-2022-31791 on the WatchGuard Advisory page at https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2022-00018