PT-2022-3467 · Watchguard · Watchguard Fireware
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
WatchGuard Fireware OS versions prior to 12.1.4
WatchGuard Fireware OS versions prior to 12.5.10
WatchGuard Fireware OS versions prior to 12.8.1
Description
An argument injection issue in the
diagnose and import pac commands allows an authenticated remote attacker with unprivileged credentials to upload or read files to limited, arbitrary locations on WatchGuard Firebox and XTM appliances.Recommendations
WatchGuard Fireware OS version prior to 12.1.4: Update to version 12.1.4 or later.
WatchGuard Fireware OS version prior to 12.5.10: Update to version 12.5.10 or later.
WatchGuard Fireware OS version prior to 12.8.1: Update to version 12.8.1 or later.
Exploit
Fix
Argument Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Watchguard Fireware