Impact
An LDAP Injection flaw in WatchGuard Fireware OS grants a remote unauthenticated attacker the ability to pull sensitive information from a linked LDAP authentication server via the exposed authentication or management web interface. The vulnerability also permits the attacker to authenticate as an LDAP user with a partial identifier if they possess that user’s correct passphrase. The flaw stems from insufficient input validation during LDAP query construction, exposing confidentiality and potentially allowing unauthorized access.
Affected Systems
The affected system is WatchGuard Fireware OS. Specific affected versions are not listed in the CVE payload, but the vulnerability is present in this product family.
Risk and Exploitability
The CVSS base score is 7, indicating high severity, while the EPSS score of less than 1% suggests the likelihood of exploitation is still low. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector involves a remote attacker sending crafted LDAP search strings via the unauthorized web interface, gaining access to sensitive entries or authenticating as a user. No authentication is required to trigger the injection, increasing the potential impact on organizations that expose these interfaces publicly.
OpenCVE Enrichment