Skip to content
COOEY

EXPOSURES › CVE-2022-23176

CVE-2022-23176

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-04-11 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2022-23176 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 exploited-in-wildunpatchedprivilege-escalationransomware

WatchGuard Firebox and XTM appliances allow remote attackers with unprivileged credentials to escalate to privileged management sessions via exposed management access.

This privilege escalation flaw lets unauthenticated attackers bypass access controls to gain administrative control, directly violating CMMC/NIST 800-171 requirements for access control and system integrity. DIB organizations must verify patch levels on all WatchGuard hardware and enforce strict management access policies to prevent unauthorized escalation. The vulnerability is actively exploited in the wild, indicating a high risk of compromise if unpatched.

Shame score — A known privilege escalation vulnerability in a widely deployed security appliance was actively exploited in the wild, demonstrating severe negligence in patching and access control.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

WatchGuard Firebox and XTM appliances allow a remote attacker with unprivileged credentials to access the system with a privileged management session via exposed management access.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.