PT-2017-13582 · Watchguard · Watchguard Fireware

Published

2017-09-20

·

Updated

2017-10-04

·

CVE-2017-14616

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions WatchGuard Fireware versions prior to 12.0
Description A issue was discovered in the XML-RPC interface where a login attempt with an XML message containing an empty member element causes the wgagent to crash. This results in any user with an open session in the UI being logged out. Continuous execution of failed login attempts can render UI management of the device impossible.
Recommendations For versions prior to 12.0, update to version 12.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the XML-RPC interface to minimize the risk of exploitation. Avoid using empty member elements in XML messages to the XML-RPC interface until the issue is resolved.

Exploit

Fix

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2017-14616

Affected Products

Watchguard Fireware