5
CVSSv2

CVE-2017-8056

Published: 22/04/2017 Updated: 27/04/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 5.3 | Impact Score: 1.4 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

WatchGuard Fireware v11.12.1 and previous versions mishandles requests referring to an XML External Entity (XXE), in the XML-RPC agent. This causes the Firebox wgagent process to crash. This process crash ends all authenticated sessions to the Firebox, including management connections, and prevents new authenticated sessions until the process has recovered. The Firebox may also experience an overall degradation in performance while the wgagent process recovers. An attacker could continuously send XML-RPC requests that contain references to external entities to perform a limited Denial of Service (DoS) attack against an affected Firebox.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

watchguard fireware

Exploits

Watchguard's Firebox and XTM appliances suffer from an XML-RPC empty member denial of service vulnerability Firmware versions below 120 were found to be vulnerable ...