Vulnerability Details CVE-2022-31790
WatchGuard Firebox and XTM appliances allow an unauthenticated remote attacker to retrieve sensitive authentication server settings by sending a malicious request to exposed authentication endpoints. This is fixed in Fireware OS 12.8.1, 12.5.10, and 12.1.4.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 58.6%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2022-31790
-
cpe:2.3:o:watchguard:fireware:12.0.0
-
cpe:2.3:o:watchguard:fireware:12.1.3
-
cpe:2.3:o:watchguard:fireware:12.2.0
-
cpe:2.3:o:watchguard:fireware:12.5.7
-
cpe:2.3:o:watchguard:fireware:12.5.9
-
cpe:2.3:o:watchguard:fireware:12.6.1
-
cpe:2.3:o:watchguard:fireware:12.6.3
-
cpe:2.3:o:watchguard:fireware:12.6.4
-
cpe:2.3:o:watchguard:fireware:12.7.0
-
cpe:2.3:o:watchguard:fireware:12.7.1
-
cpe:2.3:o:watchguard:fireware:12.7.2
-
cpe:2.3:o:watchguard:fireware:12.8.0