CVE-2022-31749

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Jan 28, 2025
CWE ID 88

Summary

CVE-2022-31749 is a vulnerability affecting WatchGuard Fireware OS versions before 12.8.1, 12.1.4, and 12.5.10. An attacker with unprivileged credentials can exploit an argument injection issue in the diagnose and import pac commands. This flaw enables the attacker to upload or read files to restricted areas on WatchGuard Firebox and XTM appliances, posing a potential security risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share