CVE-2022-25291

CVSS 8.8 - HIGH
Description

An integer overflow in WatchGuard Firebox and XTM appliances allows an authenticated remote attacker to trigger a heap-based buffer overflow and potentially execute arbitrary code by initiating a firmware update with a malicious upgrade image. This vulnerability impacts Fireware OS before 12.7.2_U2, 12.x before 12.1.3_U8, and 12.2.x through 12.5.x before 12.5.9_U2.

Affected Products
15
Vendor Product Version
watchguard fireware All versions
watchguard fireware All versions
watchguard fireware All versions
watchguard fireware 12.1.3
watchguard fireware 12.1.3
watchguard fireware 12.1.3
watchguard fireware 12.1.3
watchguard fireware 12.1.3
watchguard fireware 12.1.3
watchguard fireware 12.1.3
watchguard fireware 12.1.3
watchguard fireware 12.5.9
watchguard fireware 12.5.9
watchguard fireware 12.7.2
watchguard fireware 12.7.2
Weakness Types
CWE-190
CVE Information
CVE ID:
CVE-2022-25291
Published:
2022-02-24
Modified:
2024-11-21
CVSS Score:
8.8
Severity:
HIGH
Vector:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Vendors
watchguard
Quick Actions
CVSS Severity Scale
0.0 - 3.9 LOW
4.0 - 6.9 MEDIUM
7.0 - 8.9 HIGH
9.0 - 10.0 CRITICAL