CVE-2022-23176 is a critical vulnerability affecting WatchGuard Firebox and XTM appliances running Fireware OS before versions 12.7.2_U1, 12.1.3_U3, and 12.5.7_U3. This flaw allows a remote attacker with unprivileged credentials to gain privileged management access to the system. With a CVSS score of 8.8 (HIGH), the vulnerability has a low attack complexity and can lead to complete compromise of confidentiality, integrity, and availability. Notably, this CVE is actively exploited in the wild, as confirmed by its presence in the KEV catalog and multiple media reports, including those detailing exploitation by Russian state-sponsored actors. Despite no public exploit code being available on Metasploit, Nuclei, or ExploitDB, its high community discussion and media coverage highlight its significant threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 12.0.0, < 12.1.3CPE matchmatch criteria | cpe:2.3:o:watchguard:fireware:*:*:*:*:*:*:*:* | ||
>= 12.2.0, < 12.5.7CPE matchmatch criteria | cpe:2.3:o:watchguard:fireware:*:*:*:*:*:*:*:* | ||
12.1.3CPE matchmatch criteria | cpe:2.3:o:watchguard:fireware:12.1.3:-:*:*:*:*:*:* | ||
12.1.3CPE matchmatch criteria | cpe:2.3:o:watchguard:fireware:12.1.3:u1:*:*:*:*:*:* | ||
12.1.3CPE matchmatch criteria | cpe:2.3:o:watchguard:fireware:12.1.3:u2:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.