7.2

CVE-2024-5974

A buffer overflow in WatchGuard Fireware OS could may allow an authenticated remote attacker with privileged management access to execute arbitrary code with system privileges on the firewall.
This issue affects Fireware OS: from 11.9.6 through 12.10.3.

Data is provided by the National Vulnerability Database (NVD)
WatchguardFireware Version >= 11.9.4 < 12.5.12
   WatchguardFirebox M200 Version-
   WatchguardFirebox M270 Version-
   WatchguardFirebox M290 Version-
   WatchguardFirebox M300 Version-
   WatchguardFirebox M370 Version-
   WatchguardFirebox M390 Version-
   WatchguardFirebox M400 Version-
   WatchguardFirebox M440 Version-
   WatchguardFirebox M470 Version-
   WatchguardFirebox M4800 Version-
   WatchguardFirebox M500 Version-
   WatchguardFirebox M570 Version-
   WatchguardFirebox M5800 Version-
   WatchguardFirebox M590 Version-
   WatchguardFirebox M670 Version-
   WatchguardFirebox M690 Version-
   WatchguardFirebox T10 Version-
   WatchguardFirebox T10-d Version-
   WatchguardFirebox T10-w Version-
   WatchguardFirebox T15 Version-
   WatchguardFirebox T15-w Version-
   WatchguardFirebox T20 Version-
   WatchguardFirebox T20-w Version-
   WatchguardFirebox T30 Version-
   WatchguardFirebox T30-w Version-
   WatchguardFirebox T35 Version-
   WatchguardFirebox T35-r Version-
   WatchguardFirebox T35-w Version-
   WatchguardFirebox T40 Version-
   WatchguardFirebox T40-w Version-
   WatchguardFirebox T50 Version-
   WatchguardFirebox T50-w Version-
   WatchguardFirebox T55 Version-
   WatchguardFirebox T55-w Version-
   WatchguardFirebox T70 Version-
   WatchguardFirebox T80 Version-
   WatchguardFirebox Xtm1520-rp Version-
   WatchguardFirebox Xtm1525-rp Version-
   WatchguardFirebox Xtm2520 Version-
   WatchguardFirebox Xtm850 Version-
   WatchguardFirebox Xtm860 Version-
   WatchguardFirebox Xtm870 Version-
   WatchguardFirebox Xtm870-f Version-
   WatchguardFireboxcloud Version-
   WatchguardFireboxt Nv5
   WatchguardFireboxt T25
   WatchguardFireboxt T45
   WatchguardFireboxt T85
   WatchguardFireboxv Version-
   WatchguardXtmv Version-
WatchguardFireware Version >= 12.6 < 12.10.4
   WatchguardFirebox M200 Version-
   WatchguardFirebox M270 Version-
   WatchguardFirebox M290 Version-
   WatchguardFirebox M300 Version-
   WatchguardFirebox M370 Version-
   WatchguardFirebox M390 Version-
   WatchguardFirebox M400 Version-
   WatchguardFirebox M440 Version-
   WatchguardFirebox M470 Version-
   WatchguardFirebox M4800 Version-
   WatchguardFirebox M500 Version-
   WatchguardFirebox M570 Version-
   WatchguardFirebox M5800 Version-
   WatchguardFirebox M590 Version-
   WatchguardFirebox M670 Version-
   WatchguardFirebox M690 Version-
   WatchguardFirebox T10 Version-
   WatchguardFirebox T10-d Version-
   WatchguardFirebox T10-w Version-
   WatchguardFirebox T15 Version-
   WatchguardFirebox T15-w Version-
   WatchguardFirebox T20 Version-
   WatchguardFirebox T20-w Version-
   WatchguardFirebox T30 Version-
   WatchguardFirebox T30-w Version-
   WatchguardFirebox T35 Version-
   WatchguardFirebox T35-r Version-
   WatchguardFirebox T35-w Version-
   WatchguardFirebox T40 Version-
   WatchguardFirebox T40-w Version-
   WatchguardFirebox T50 Version-
   WatchguardFirebox T50-w Version-
   WatchguardFirebox T55 Version-
   WatchguardFirebox T55-w Version-
   WatchguardFirebox T70 Version-
   WatchguardFirebox T80 Version-
   WatchguardFirebox Xtm1520-rp Version-
   WatchguardFirebox Xtm1525-rp Version-
   WatchguardFirebox Xtm2520 Version-
   WatchguardFirebox Xtm850 Version-
   WatchguardFirebox Xtm860 Version-
   WatchguardFirebox Xtm870 Version-
   WatchguardFirebox Xtm870-f Version-
   WatchguardFireboxcloud Version-
   WatchguardFireboxt Nv5
   WatchguardFireboxt T25
   WatchguardFireboxt T45
   WatchguardFireboxt T85
   WatchguardFireboxv Version-
   WatchguardXtmv Version-
WatchguardFireware Version12.5.12 Updateu1
   WatchguardFirebox M200 Version-
   WatchguardFirebox M270 Version-
   WatchguardFirebox M290 Version-
   WatchguardFirebox M300 Version-
   WatchguardFirebox M370 Version-
   WatchguardFirebox M390 Version-
   WatchguardFirebox M400 Version-
   WatchguardFirebox M440 Version-
   WatchguardFirebox M470 Version-
   WatchguardFirebox M4800 Version-
   WatchguardFirebox M500 Version-
   WatchguardFirebox M570 Version-
   WatchguardFirebox M5800 Version-
   WatchguardFirebox M590 Version-
   WatchguardFirebox M670 Version-
   WatchguardFirebox M690 Version-
   WatchguardFirebox T10 Version-
   WatchguardFirebox T10-d Version-
   WatchguardFirebox T10-w Version-
   WatchguardFirebox T15 Version-
   WatchguardFirebox T15-w Version-
   WatchguardFirebox T20 Version-
   WatchguardFirebox T20-w Version-
   WatchguardFirebox T30 Version-
   WatchguardFirebox T30-w Version-
   WatchguardFirebox T35 Version-
   WatchguardFirebox T35-r Version-
   WatchguardFirebox T35-w Version-
   WatchguardFirebox T40 Version-
   WatchguardFirebox T40-w Version-
   WatchguardFirebox T50 Version-
   WatchguardFirebox T50-w Version-
   WatchguardFirebox T55 Version-
   WatchguardFirebox T55-w Version-
   WatchguardFirebox T70 Version-
   WatchguardFirebox T80 Version-
   WatchguardFirebox Xtm1520-rp Version-
   WatchguardFirebox Xtm1525-rp Version-
   WatchguardFirebox Xtm2520 Version-
   WatchguardFirebox Xtm850 Version-
   WatchguardFirebox Xtm860 Version-
   WatchguardFirebox Xtm870 Version-
   WatchguardFirebox Xtm870-f Version-
   WatchguardFireboxcloud Version-
   WatchguardFireboxt Nv5
   WatchguardFireboxt T25
   WatchguardFireboxt T45
   WatchguardFireboxt T85
   WatchguardFireboxv Version-
   WatchguardXtmv Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 5.5% 0.899
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
5d1c2695-1a31-4499-88ae-e847036fd7e3 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer, leading to a buffer overflow.