Security Advisory Detail

Firebox WebUI Business Logic Vulnerability

Advisory ID
WGSA-2021-00005
Impact
High
Status
Resolved
Product Family
Firebox
Published Date
Updated Date
Workaround Available
False
CVSS Score
7.2
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Summary

The Firebox WebUI has a business logic flaw that could allow an attacker to obtain a limited authenticated session on the system via exposed management access.

Affected

Fireware OS before 12.7.2_U1, 12.x before 12.1.3_U7, 12.2.x through 12.5.x before 12.5.9_U1.

Resolution

Fireware OS 12.7.2_U1, 12.1.3_U7, 12.5.9_U1

Credits
Internally discovered
Advisory Product List
Product Family Product Branch Product List
Firebox
Fireware OS 12.x T20, T25, T40, T45, T55, T70, T80, T85, M270, M290, M370, M390, M470, M570, M590, M670, M690, M440, M4600, M4800, M5600, M5800, Firebox Cloud, Firebox NV5, FireboxV
Firebox
Fireware OS 12.5.x T15, T35