NONE · 0

CVE-2025-6947

A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the SIP Proxy configuration. An authenticated remote attacker with administrat...

Vulnerability Description

A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the SIP Proxy configuration. An authenticated remote attacker with administrator privileges could exploit this vulnerability to execute arbitrary JavaScript code in the Firebox management interface of another management user.

Related Weaknesses (CWE)

References

FAQ

What is CVE-2025-6947?

CVE-2025-6947 is a documented vulnerability. A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the SIP Proxy configuration. An authenticated remote attacker with administrat...

How severe is CVE-2025-6947?

CVSS scoring is not yet available for CVE-2025-6947. Check NVD for updates.

Is there a patch for CVE-2025-6947?

Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.