High severity8.8CISA KEVNVD Advisory· Published Feb 24, 2022· Updated Jun 17, 2026
CVE-2022-23176
CVE-2022-23176
Description
WatchGuard Firebox and XTM appliances allow a remote attacker with unprivileged credentials to access the system with a privileged management session via exposed management access. This vulnerability impacts Fireware OS before 12.7.2_U1, 12.x before 12.1.3_U3, and 12.2.x through 12.5.x before 12.5.7_U3.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
12cpe:2.3:o:watchguard:fireware:*:*:*:*:*:*:*:*+ 8 more
- cpe:2.3:o:watchguard:fireware:*:*:*:*:*:*:*:*range: >=12.0.0,<12.1.3
- cpe:2.3:o:watchguard:fireware:12.1.3:-:*:*:*:*:*:*
- cpe:2.3:o:watchguard:fireware:12.1.3:u1:*:*:*:*:*:*
- cpe:2.3:o:watchguard:fireware:12.1.3:u2:*:*:*:*:*:*
- cpe:2.3:o:watchguard:fireware:12.5.7:-:*:*:*:*:*:*
- cpe:2.3:o:watchguard:fireware:12.5.7:u1:*:*:*:*:*:*
- cpe:2.3:o:watchguard:fireware:12.5.7:u2:*:*:*:*:*:*
- cpe:2.3:o:watchguard:fireware:12.7.2:-:*:*:*:*:*:*
- (no CPE)range: <12.7.2_U1, <12.1.3_U3, <12.5.7_U3
- WatchGuard/Firebox and XTM appliancesdescription
- Range: <12.7.2_U1, <12.1.3_U3, <12.5.7_U3
- Range: <12.7.2_U1, <12.1.3_U3, <12.5.7_U3
Patches
Vulnerability mechanics
References
6- arstechnica.com/information-technology/2022/04/watchguard-failed-to-disclose-critical-flaw-exploited-by-russian-hackers/nvdThird Party Advisory
- securityportal.watchguard.comnvdVendor Advisory
- www.watchguard.com/support/release-notes/fireware/12/en-US/EN_ReleaseNotes_Fireware_12_1_3_U7/index.htmlnvdRelease NotesVendor Advisory
- www.watchguard.com/support/release-notes/fireware/12/en-US/EN_ReleaseNotes_Fireware_12_7/index.htmlnvdRelease NotesVendor Advisory
- www.watchguard.com/support/release-notes/fireware/12/en-US/EN_ReleaseNotes_Fireware_12_7_2/index.htmlnvdRelease NotesVendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
0No linked articles in our index yet.