Firebox WebUI Stored Cross-Site Scripting (XSS) Vulnerability
A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox and XTM appliances. An unauthenticated remote attacker can potentially execute arbitrary JavaScript code in the Firebox management interface by sending carefully crafted requests to exposed management ports.
Fireware OS before 12.8.1, 12.x before 12.1.4, and 12.2.x through 12.5.x before 12.5.10.
Fireware OS 12.8.1, 12.5.10 and 12.1.4
Product Family | Product Branch | Product List |
---|---|---|
Firebox
|
Fireware OS 12.x | T20, T25, T40, T45, T55, T70, T80, T85, M270, M290, M370, M390, M470, M570, M590, M670, M690, M440, M4600, M4800, M5600, M5800, Firebox Cloud, Firebox NV5, FireboxV |
Firebox
|
Fireware OS 12.5.x | T15, T35 |