4.8

CVE-2025-6946

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS allows Stored XSS via the IPS module. This vulnerability requires an authenticated administrator session to a locally managed Firebox.

This issue affects Firebox: from 12.0 through 12.11.2.
Verknüpft mit AI von unstrukturierten Daten zu bestehenden CPE der NVD
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
WatchguardFireware Version >= 12.0.0 < 12.11.3
   WatchguardFirebox M270 Version-
   WatchguardFirebox M290 Version-
   WatchguardFirebox M370 Version-
   WatchguardFirebox M390 Version-
   WatchguardFirebox M440 Version-
   WatchguardFirebox M4600 Version-
   WatchguardFirebox M470 Version-
   WatchguardFirebox M4800 Version-
   WatchguardFirebox M5600 Version-
   WatchguardFirebox M570 Version-
   WatchguardFirebox M5800 Version-
   WatchguardFirebox M590 Version-
   WatchguardFirebox M670 Version-
   WatchguardFirebox M690 Version-
   WatchguardFirebox Nv5 Version-
   WatchguardFirebox T20 Version-
   WatchguardFirebox T25 Version-
   WatchguardFirebox T40 Version-
   WatchguardFirebox T45 Version-
   WatchguardFirebox T55 Version-
   WatchguardFirebox T70 Version-
   WatchguardFirebox T80 Version-
   WatchguardFirebox T85 Version-
   WatchguardFireboxcloud Version-
   WatchguardFireboxv Version-
WatchguardFireware Version >= 12.5 < 12.5.13
   WatchguardFirebox T15 Version-
   WatchguardFirebox T35 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.03% 0.075
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 4.8 1.7 2.7
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:L/I:L/A:N
5d1c2695-1a31-4499-88ae-e847036fd7e3 4.8 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:P/VC:N/VI:N/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.