Integer Overflow Vulnerability in WatchGuard Firebox and XTM Appliances
CVE-2022-25291
8.8HIGH
What is CVE-2022-25291?
An integer overflow vulnerability in WatchGuard Firebox and XTM appliances allows an authenticated remote attacker to exploit a heap-based buffer overflow. By initiating a firmware update with a malicious upgrade image, the attacker could execute arbitrary code on affected systems. This issue impacts specific versions of Fireware OS, notably those prior to 12.7.2_U2 and various releases between 12.1.3_U8 and 12.5.9_U2.