CVE-2022-23176
high-risk
Published 2022-02-24
WatchGuard Firebox and XTM appliances allow a remote attacker with unprivileged credentials to access the system with a privileged management session via exposed management access. This vulnerability impacts Fireware OS before 12.7.2_U1, 12.x before 12.1.3_U3, and 12.2.x through 12.5.x before 12.5.7_U3.
Do I need to act?
~
9.6% chance of exploitation in next 30 days
EPSS score — moderate exploit probability
!
CISA KEV: actively exploited in the wild
On the Known Exploited Vulnerabilities catalog — federal agencies must patch
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
8
CVSS 8.8/10
High
NETWORK
/ LOW complexity
Affected Vendors
References (11)
Third Party Advisory
https://arstechnica.com/information-technology/2022/04/watchguard-failed-to-disc...
Vendor Advisory
https://securityportal.watchguard.com
Third Party Advisory
https://arstechnica.com/information-technology/2022/04/watchguard-failed-to-disc...
Vendor Advisory
https://securityportal.watchguard.com
US Government Resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-...
62
/ 100
high-risk
Severity
30/34 · Critical
Exploitability
18/34 · Moderate
Exposure
14/34 · Moderate