7.5

CVE-2022-31790

Exploit
WatchGuard Firebox and XTM appliances allow an unauthenticated remote attacker to retrieve sensitive authentication server settings by sending a malicious request to exposed authentication endpoints. This is fixed in Fireware OS 12.8.1, 12.5.10, and 12.1.4.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
WatchguardFireware Version >= 12.0.0 < 12.1.4
WatchguardFireware Version >= 12.2.0 < 12.5.10
WatchguardFireware Version12.6.1 Updateu1
WatchguardFireware Version12.6.1 Updateu3
WatchguardFireware Version12.6.3
WatchguardFireware Version12.6.4
WatchguardFireware Version12.7.0 Updateu1
WatchguardFireware Version12.7.1
WatchguardFireware Version12.7.2 Updateu2
WatchguardFireware Version12.8.0 Updateu1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.48% 0.705
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://www.ambionics.io/blog/hacking-watchguard-firewalls
Third Party Advisory
Exploit
https://www.openwall.com/lists/oss-security/2022/08/30/2
Third Party Advisory
Mailing List
https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2022-00017
Vendor Advisory