Junglewise Threat Intelligence

CVE-2022-23176: WatchGuard Firebox and XTM Privilege Escalation Vulnerability

CVE-2022-23176 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2022-04-11

Technologies: Watchguard Fireware OS, Watchguard XTM, Watchguard Firebox, Watchguard XTM Appliances. Vendors: Watchguard.

Executive brief

WatchGuard Firebox and XTM appliances running Fireware OS are vulnerable to privilege escalation. A remote attacker with unprivileged credentials can gain a privileged management session if management access is exposed.

Affected products

  • WatchGuard Fireware OS before 12.7.2_U1, 12.x before 12.1.3_U3, and 12.2.x through 12.5.x before 12.5.7_U3
  • WatchGuard Firebox
  • WatchGuard XTM

Timeline

  • 2022-04-11: disclosed
  • 2022-04-11: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-04-11: exploited: Reported as exploited in the wild by Russian hackers per advisory references.

Related threats