CVE Vulnerabilities

CVE-2022-31790

Published: Sep 06, 2022 | Modified: Sep 10, 2022
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

WatchGuard Firebox and XTM appliances allow an unauthenticated remote attacker to retrieve sensitive authentication server settings by sending a malicious request to exposed authentication endpoints. This is fixed in Fireware OS 12.8.1, 12.5.10, and 12.1.4.

Affected Software

Name Vendor Start Version End Version
Fireware Watchguard 12.0.0 (including) 12.1.4 (excluding)
Fireware Watchguard 12.2.0 (including) 12.5.10 (excluding)
Fireware Watchguard 12.6.1-u1 (including) 12.6.1-u1 (including)
Fireware Watchguard 12.6.1-u3 (including) 12.6.1-u3 (including)
Fireware Watchguard 12.6.3 (including) 12.6.3 (including)
Fireware Watchguard 12.6.4 (including) 12.6.4 (including)
Fireware Watchguard 12.7.0-u1 (including) 12.7.0-u1 (including)
Fireware Watchguard 12.7.1 (including) 12.7.1 (including)
Fireware Watchguard 12.7.2-u2 (including) 12.7.2-u2 (including)
Fireware Watchguard 12.8.0-u1 (including) 12.8.0-u1 (including)

References