CVE-2023-26237: Medium severity watchguard epp firmware vulnerability
Published Oct 5, 2023
·Updated
An issue was discovered in WatchGuard EPDR 8.0.21.0002. It is possible to bypass the defensive capabilities by adding a registry key as SYSTEM.
Affected Software
16 affected components
All of the following
WatchGuard Epp Firmware<8.00.22.0010
WatchGuard Epp
All of the following
WatchGuard Edr Firmware<8.00.22.0010
WatchGuard Edr
All of the following
WatchGuard Epdr Firmware<8.00.22.0010
WatchGuard EPDR
All of the following
WatchGuard Panda Ad360 Firmware<8.00.22.0010
WatchGuard Panda Ad360
WatchGuard Epp Firmware<8.00.22.0010
WatchGuard Epp
WatchGuard Edr Firmware<8.00.22.0010
WatchGuard Edr
WatchGuard Epdr Firmware<8.00.22.0010
WatchGuard EPDR
WatchGuard Panda Ad360 Firmware<8.00.22.0010
WatchGuard Panda Ad360
Event History
Oct 5, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2023-26237?
The severity of CVE-2023-26237 is medium.
2
How does CVE-2023-26237 affect WatchGuard EPDR?
CVE-2023-26237 allows an attacker to bypass the defensive capabilities in WatchGuard EPDR 8.0.21.0002 by adding a registry key as SYSTEM.
3
Which versions of WatchGuard EPDR are affected by CVE-2023-26237?
WatchGuard EPDR versions up to and excluding 8.00.22.0010 are affected by CVE-2023-26237.
4
How can I fix CVE-2023-26237?
To fix CVE-2023-26237, it is recommended to update to a version of WatchGuard EPDR that is later than 8.00.22.0010.
5
Where can I find more information about CVE-2023-26237?
More information about CVE-2023-26237 can be found at the official WatchGuard advisory: [https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2023-00005](https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2023-00005)