Executive brief
An unauthenticated remote attacker can execute arbitrary code on WatchGuard Firebox and XTM appliances. The vulnerability stems from a flaw in the Fireware OS and is tracked internally as FBX-22786.
Affected products
- WatchGuard Fireware OS before 12.7.2_U2, 12.x before 12.1.3_U8, and 12.2.x through 12.5.x before 12.5.9_U2
- WatchGuard Firebox
- WatchGuard XTM Appliances
Timeline
- 2022-03-15: disclosed: Initial NIST analysis date
- 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2022-03-25: advisory: NVD publication date