Vulnerability Description
An argument injection vulnerability in the diagnose and import pac commands in WatchGuard Fireware OS before 12.8.1, 12.1.4, and 12.5.10 allows an authenticated remote attacker with unprivileged credentials to upload or read files to limited, arbitrary locations on WatchGuard Firebox and XTM appliances
CVSS Score
MEDIUM
Related Weaknesses (CWE)
References
- https://www.rapid7.com/blog/post/2022/06/23/cve-2022-31749-watchguard-authentica
- https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2022-00019
FAQ
What is CVE-2022-31749?
CVE-2022-31749 is a vulnerability with a CVSS score of 6.5 (MEDIUM). An argument injection vulnerability in the diagnose and import pac commands in WatchGuard Fireware OS before 12.8.1, 12.1.4, and 12.5.10 allows an authenticated remote attacker with unprivileged crede...
How severe is CVE-2022-31749?
CVE-2022-31749 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-31749?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.