CVE Vulnerabilities

CVE-2022-25290

Published: Feb 24, 2022 | Modified: Nov 21, 2024
CVSS 3.x
6.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
4 MEDIUM
AV:N/AC:L/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

WatchGuard Firebox and XTM appliances allow an authenticated remote attacker with unprivileged credentials to retrieve certificate private keys. This vulnerability impacts Fireware OS before 12.7.2_U2, 12.x before 12.1.3_U8, and 12.2.x through 12.5.x before 12.5.9_U2.

Affected Software

NameVendorStart VersionEnd Version
FirewareWatchguard12.0.0 (including)12.1.3 (excluding)
FirewareWatchguard12.2.0 (including)12.5.9 (excluding)
FirewareWatchguard12.7.0 (including)12.7.2 (excluding)
FirewareWatchguard12.1.3 (including)12.1.3 (including)
FirewareWatchguard12.1.3-u1 (including)12.1.3-u1 (including)
FirewareWatchguard12.1.3-u2 (including)12.1.3-u2 (including)
FirewareWatchguard12.1.3-u3 (including)12.1.3-u3 (including)
FirewareWatchguard12.1.3-u4 (including)12.1.3-u4 (including)
FirewareWatchguard12.1.3-u5 (including)12.1.3-u5 (including)
FirewareWatchguard12.1.3-u6 (including)12.1.3-u6 (including)
FirewareWatchguard12.1.3-u7 (including)12.1.3-u7 (including)
FirewareWatchguard12.5.9 (including)12.5.9 (including)
FirewareWatchguard12.5.9-u1 (including)12.5.9-u1 (including)
FirewareWatchguard12.7.2 (including)12.7.2 (including)
FirewareWatchguard12.7.2-u1 (including)12.7.2-u1 (including)

References