WatchGuard security update-CVE-2022-23176
NAME
WatchGuard Technologies – Fireware
- Platforms Affected:
Fireware - Risk Level:
medium - CVE Type:
Improper privilege management
DESCRIPTION
CVE-2022-23176 is an improper privilege management vulnerability impacting multiple versions of WatchGuard Fireware OS. A proof of concept (PoC) was not observed publicly or in the underground. Additionally, security researchers at the Cybersecurity and Infrastructure Security Agency (CISA) claimed the vulnerability was actively exploited in the wild.
CVSS Information:
- CVSS 2.0 SCORE: 9
- CVSS 3.0 SCORE: 8.8
- Exploit Disclosed in the Public:
true - Exploit Weaponised:
true - PoC Link:
hXXps://www[.]cisa[.]gov/known-exploited-vulnerabilities-catalog
MITIGATION
WatchGuard Technologies addressed the vulnerability in a security advisory with updated versions.
- Reference Link:
https://www.watchguard.com/support/release-notes/fireware/12/en-US/EN_ReleaseNotes_Fireware_12_1_3_U7/index.html#Fireware/en-US/resolved_issues.html - Patch Available:
available
If you like the site, please consider joining the telegram channel and supporting us on Patreon using the button below.