Impact
A path traversal flaw in the Fireware OS Web UI allows an authenticated user with elevated privileges to overwrite arbitrary files on the device. The revised description confirms that this can lead to execution of malicious code within the context of an elevated system process, effectively granting the attacker full control over the firewall and undermining confidentiality, integrity, and availability.
Affected Systems
WatchGuard Fireware OS installations on Firebox devices.
Risk and Exploitability
The CVSS base score of 8.6 indicates a high severity vulnerability. The EPSS score of < 1% shows a very low but non-zero probability of exploitation. The vulnerability is not listed in the CISA KEV catalog. The flaw requires remote access to the Web UI and valid credentials with elevated privileges; thus, the attack vector is remote authenticated. Once an attacker authenticates, they can exploit the path traversal to place malicious files that the system process will execute.
OpenCVE Enrichment