Firebox Authenticated Stack Overflow Vulnerability va CLI Interface
Advisory ID
WGSA-2022-00016
CVE
CVE-2022-25362
Impact
Critical
Status
Resolved
Product Family
Firebox
Published Date
Updated Date
Workaround Available
False
CVSS Score
8.8
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Summary
A Stack-based overflow in WatchGuard Firebox and XTM appliances allows an authenticated remote attacker to potentially execute arbitrary code by initiating a firmware update with a malicious upgrade image from the command line interface.
Affected
Fireware OS before 12.8, 12.x before 12.1.4, and 12.2.x through 12.5.x before 12.5.10.