PT-2017-13582 · Watchguard · Watchguard Fireware
Published
2017-09-20
·
Updated
2017-10-04
·
CVE-2017-14616
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
WatchGuard Fireware versions prior to 12.0
Description
A issue was discovered in the XML-RPC interface where a login attempt with an XML message containing an empty member element causes the wgagent to crash. This results in any user with an open session in the UI being logged out. Continuous execution of failed login attempts can render UI management of the device impossible.
Recommendations
For versions prior to 12.0, update to version 12.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the XML-RPC interface to minimize the risk of exploitation. Avoid using empty member elements in XML messages to the XML-RPC interface until the issue is resolved.
Exploit
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Watchguard Fireware