Skip to main content

CVE-2022-23176

8.8
HIGHCVSS v3.1 Base Score
10.17%
LOW RiskEPSS (93rd percentile)
KEV
NVD-CWE-noinfo

WatchGuard Firebox and XTM appliances allow a remote attacker with unprivileged credentials to access the system with a privileged management session via exposed management access. This vulnerability impacts Fireware OS before 12.7.2_U1, 12.x before 12.1.3_U3, and 12.2.x through 12.5.x before 12.5.7_U3.

Published: 2/24/2022
Modified: 11/3/2025
Back to CVE Lookup

ACTIVELY EXPLOITED IN THE WILD

This vulnerability is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog.

Vulnerability Name:

WatchGuard Firebox and XTM Privilege Escalation Vulnerability

Vendor / Product:

WatchGuard Firebox and XTM

Required Action:

Apply updates per vendor instructions.

Due Date: 5/2/2022(OVERDUE)
Added to KEV:

4/11/2022

Notes:

https://nvd.nist.gov/vuln/detail/CVE-2022-23176

Vulnerability Summary

CVSS v3 Score

8.8HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS v2 Score

9

AV:N/AC:L/Au:S/C:C/I:C/A:C

EPSS Score (Exploitation Probability)

10.17%LOW Exploitation Risk
93rd percentile

This vulnerability has a 10.17% probability of being exploited in the next 30 days, ranking higher than 93% of all scored CVEs.

CWE Classification

NVD-CWE-noinfo

Related Vulnerabilities