PT-2022-20937 · Watchguard · Watchguard Xtm+2

Published

2022-09-06

·

Updated

2022-09-09

·

CVE-2022-31792

CVSS v3.1

5.4

Medium

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions WatchGuard Firebox and XTM appliances versions prior to 12.1.4 WatchGuard Firebox and XTM appliances versions prior to 12.5.10 WatchGuard Firebox and XTM appliances versions prior to 12.8.1
Description A stored cross-site scripting (XSS) issue exists in the management web interface, allowing a remote attacker to execute arbitrary JavaScript code by sending crafted requests to exposed management ports.
Recommendations For versions prior to 12.1.4, update to Fireware OS 12.1.4 or later. For versions prior to 12.5.10, update to Fireware OS 12.5.10 or later. For versions prior to 12.8.1, update to Fireware OS 12.8.1 or later.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2022-31792

Affected Products

Fireware Os
Watchguard Firebox
Watchguard Xtm