Advisory ID
WGSA-2021-00005
Published Date
2021-12-30
Workaround Available
False
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Summary
The Firebox WebUI has a business logic flaw that could allow an attacker to obtain a limited authenticated session on the system via exposed management access.
Affected
Fireware OS before 12.7.2_U1, 12.x before 12.1.3_U7, 12.2.x through 12.5.x before 12.5.9_U1.
Resolution
Fireware OS 12.7.2_U1, 12.1.3_U7, 12.5.9_U1
Credits
Internally discovered
Advisory Product List
Product Family
Product Branch
Product List
XTM 8 Series (2nd Gen)
XTM850,
XTM860,
XTM870,
XTM870-F
XTM 1500 and 2520
XTM1520-RP,
XTM1525-RP,
XTM2520
Firebox T (1st Gen)
T10,
T10-W,
T10-D,
T30,
T30-W,
T50,
T50-W
Firebox T (2nd Gen)
T15,
T15-W,
T35,
T35-W,
T35-R,
T55,
T55-W,
T70
Firebox M (1st Gen)
M200,
M300,
M400,
M440,
M500
Firebox M (2nd Gen)
M270,
M370,
M470,
M570,
M670
Firebox T (3rd Gen)
T20,
T20-W,
T40,
T40-W,
T80
Firebox M (3rd Gen)
M290,
M390,
M590,
M690,
M4800,
M5800
XTMv
Small,
Medium,
Large,
Datacenter
FireboxV
Small,
Medium,
Large,
XLarge
FireboxCloud
Small,
Medium,
Large,
XLarge