Security Advisory

CVE-2022-25291

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2022-02-24 04:57:04
Last updated 2024-08-03 04:36:06
Assigner mitre
State PUBLISHED

Description

An integer overflow in WatchGuard Firebox and XTM appliances allows an authenticated remote attacker to trigger a heap-based buffer overflow and potentially execute arbitrary code by initiating a firmware update with a malicious upgrade image. This vulnerability impacts Fireware OS before 12.7.2_U2, 12.x before 12.1.3_U8, and 12.2.x through 12.5.x before 12.5.9_U2.