PT-2017-13582 · Watchguard · Watchguard Fireware

Publicado

2017-09-20

·

Atualizado

2017-10-04

·

CVE-2017-14616

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions WatchGuard Fireware versions prior to 12.0
Description A issue was discovered in the XML-RPC interface where a login attempt with an XML message containing an empty member element causes the wgagent to crash. This results in any user with an open session in the UI being logged out. Continuous execution of failed login attempts can render UI management of the device impossible.
Recommendations For versions prior to 12.0, update to version 12.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the XML-RPC interface to minimize the risk of exploitation. Avoid using empty member elements in XML messages to the XML-RPC interface until the issue is resolved.

Exploit

Correção

Resource Exhaustion

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2017-14616

Produtos afetados

Watchguard Fireware