Impact
In certain exceptional circumstances, devices running WatchGuard Fireware OS as part of a FireCluster use a hard-coded fallback encryption key to encrypt stored credentials for Access Portal resources. This weakness (CWE-798) permits an attacker who can read the credential database to recover usernames and passwords, compromising authenticated sessions and undermining credential confidentiality. The flaw is limited to FireCluster deployments with the Access Portal feature enabled; devices that do not support Access Portal or are standalone Fireboxes not in a FireCluster are not affected.
Affected Systems
WatchGuard Fireware OS devices that are part of a FireCluster and have the Access Portal feature enabled are affected. Devices that do not support the Access Portal feature or standalone Fireboxes not deployed in a FireCluster are not impacted.
Risk and Exploitability
The CVSS score of 5.9 indicates a moderate risk, while an EPSS score of less than 1% suggests a very low probability of exploitation. Because the flaw only weakens the encryption of the credential database, an attacker must first obtain read access to that database, implying a prerequisite compromise. The vulnerability is not listed in CISA KEV and no public exploitation has been reported. Were the database accessed, credential compromise would be possible.
OpenCVE Enrichment