An argument injection vulnerability in the diagnose and import pac commands in WatchGuard Fireware OS before 12.8.1, 12.1.4, and 12.5.10 allows an authenticated remote attacker with unprivileged credentials to upload or read files to limited, arbitrary locations on WatchGuard Firebox and XTM appliances
Metrics
Affected Vendors & Products
References
History
Tue, 28 Jan 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 27 Jan 2025 23:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An argument injection vulnerability in the diagnose and import pac commands in WatchGuard Fireware OS before 12.8.1, 12.1.4, and 12.5.10 allows an authenticated remote attacker with unprivileged credentials to upload or read files to limited, arbitrary locations on WatchGuard Firebox and XTM appliances | |
Title | Authenticated arbitrary file read/write in WatchGuard Fireware OS | |
Weaknesses | CWE-88 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: rapid7
Published:
Updated: 2025-01-28T15:18:35.068Z
Reserved: 2022-05-26T17:58:55.663Z
Link: CVE-2022-31749

Updated: 2025-01-28T14:47:38.119Z

Status : Received
Published: 2025-01-28T00:15:06.487
Modified: 2025-01-28T00:15:06.487
Link: CVE-2022-31749

No data.