CVE-2026-3343
Estado: ModificadaMedia (5.1)—
A reflected cross-site scripting (XSS) vulnerability in the Fireware OS Web UI enabled execution of malicious JavaScript in the context of an authenticated management user's browser when they click on a specially crafted link.
CVSS
- Versión: 4.0
- Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- Puntuación base: 5.1
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.34%
- Percentil entre todas las CVEs puntuadas: 25
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-79
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2026-3343",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2026-3343",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2026-03-03T14:44:26.500886Z"
}
}
],
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 6.1,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "NONE",
"confidentialityImpact": "LOW"
},
"impactScore": 2.7,
"exploitabilityScore": 2.8
}
],
"cvssMetricV40": [
{
"type": "Secondary",
"source": "5d1c2695-1a31-4499-88ae-e847036fd7e3",
"cvssData": {
"Safety": "NOT_DEFINED",
"version": "4.0",
"Recovery": "NOT_DEFINED",
"baseScore": 5.1,
"Automatable": "NOT_DEFINED",
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"valueDensity": "NOT_DEFINED",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X",
"exploitMaturity": "NOT_DEFINED",
"providerUrgency": "NOT_DEFINED",
"userInteraction": "ACTIVE",
"attackComplexity": "LOW",
"attackRequirements": "NONE",
"privilegesRequired": "NONE",
"subIntegrityImpact": "NONE",
"vulnIntegrityImpact": "LOW",
"integrityRequirement": "NOT_DEFINED",
"modifiedAttackVector": "NOT_DEFINED",
"subAvailabilityImpact": "NONE",
"vulnAvailabilityImpact": "NONE",
"availabilityRequirement": "NOT_DEFINED",
"modifiedUserInteraction": "NOT_DEFINED",
"modifiedAttackComplexity": "NOT_DEFINED",
"subConfidentialityImpact": "NONE",
"vulnConfidentialityImpact": "LOW",
"confidentialityRequirement": "NOT_DEFINED",
"modifiedAttackRequirements": "NOT_DEFINED",
"modifiedPrivilegesRequired": "NOT_DEFINED",
"modifiedSubIntegrityImpact": "NOT_DEFINED",
"modifiedVulnIntegrityImpact": "NOT_DEFINED",
"vulnerabilityResponseEffort": "NOT_DEFINED",
"modifiedSubAvailabilityImpact": "NOT_DEFINED",
"modifiedVulnAvailabilityImpact": "NOT_DEFINED",
"modifiedSubConfidentialityImpact": "NOT_DEFINED",
"modifiedVulnConfidentialityImpact": "NOT_DEFINED"
}
}
]
},
"affected": [
{
"source": "5d1c2695-1a31-4499-88ae-e847036fd7e3",
"affectedData": [
{
"vendor": "WatchGuard",
"product": "Fireware OS",
"versions": [
{
"status": "affected",
"version": "2025.1",
"lessThan": "2026.1.2",
"versionType": "custom"
},
{
"status": "affected",
"version": "12.7",
"lessThan": "12.11.8",
"versionType": "custom"
}
],
"platforms": [
"Default"
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2026-03-03T14:15:57.687",
"references": [
{
"url": "https://psirt.watchguard.com/CVE-2026-3343",
"source": "5d1c2695-1a31-4499-88ae-e847036fd7e3"
},
{
"url": "https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2026-00004",
"tags": [
"Vendor Advisory"
],
"source": "5d1c2695-1a31-4499-88ae-e847036fd7e3"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "5d1c2695-1a31-4499-88ae-e847036fd7e3",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A reflected cross-site scripting (XSS) vulnerability in the Fireware OS Web UI enabled execution of malicious JavaScript in the context of an authenticated management user's browser when they click on a specially crafted link."
},
{
"lang": "es",
"value": "Una vulnerabilidad de cross-site scripting (XSS) reflejada en la interfaz de usuario web de Fireware OS permitió la ejecución de JavaScript malicioso en el contexto del navegador de un usuario de gestión autenticado cuando hacen clic en un enlace especialmente diseñado.\n\nEsta vulnerabilidad afecta a Fireware OS 12.7 hasta e incluyendo 12.11.7 y 2025.1 hasta e incluyendo 2026.1.1."
}
],
"lastModified": "2026-08-10T17:17:34.027",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:watchguard:fireware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5A96DE7F-D807-4BC7-BECE-D0281939D36C",
"versionEndExcluding": "12.11.8",
"versionStartIncluding": "12.7"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:watchguard:firebox_m270:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "E472917E-D6E1-4C2D-B37D-E76FCC7307CA"
},
{
"criteria": "cpe:2.3:h:watchguard:firebox_m290:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "9A8C7779-4466-4A9E-B191-929E7746DFF7"
},
{
"criteria": "cpe:2.3:h:watchguard:firebox_m370:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "6CE9A123-B769-4E56-845E-DC3DA6166C78"
},
{
"criteria": "cpe:2.3:h:watchguard:firebox_m390:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "180FAE8C-2E73-4C09-AA11-0C82A7715FA3"
},
{
"criteria": "cpe:2.3:h:watchguard:firebox_m440:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "309DBEF2-1D92-4641-827F-D99758B5FFA3"
},
{
"criteria": "cpe:2.3:h:watchguard:firebox_m4600:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "D1E8CFC5-51FE-4D75-845F-D70C30AF11B0"
},
{
"criteria": "cpe:2.3:h:watchguard:firebox_m470:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "BBFBA966-E052-4350-9544-3B5D484DBB6B"
},
{
"criteria": "cpe:2.3:h:watchguard:firebox_m4800:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "EF1E586D-0E88-447A-95E8-5203EF869ADB"
},
{
"criteria": "cpe:2.3:h:watchguard:firebox_m5600:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "1BC087C4-CB10-46D4-A746-0C462354410C"
},
{
"criteria": "cpe:2.3:h:watchguard:firebox_m570:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "59389EA2-3067-4AF8-AEC5-FE79E269C170"
},
{
"criteria": "cpe:2.3:h:watchguard:firebox_m5800:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "445FA7CD-D0AE-4176-9AE5-293B918DE654"
},
{
"criteria": "cpe:2.3:h:watchguard:firebox_m590:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "1B4A7366-0304-431E-B3E4-719BA575CEAC"
},
{
"criteria": "cpe:2.3:h:watchguard:firebox_m670:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "E8512B4A-5269-4067-B9C6-475A4E8AD313"
},
{
"criteria": "cpe:2.3:h:watchguard:firebox_m690:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "179C6166-87E1-44F8-B727-CDDE40C673D9"
},
{
"criteria": "cpe:2.3:h:watchguard:firebox_nv5:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "584107CC-6136-4AA1-AE68-73B93BDDB5B6"
},
{
"criteria": "cpe:2.3:h:watchguard:firebox_t20:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "9295217E-C1A0-4A69-A0F0-C44814BB376C"
},
{
"criteria": "cpe:2.3:h:watchguard:firebox_t25:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "7DC49246-2166-4681-8D67-4C0940884872"
},
{
"criteria": "cpe:2.3:h:watchguard:firebox_t40:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "CC853916-8BDC-4F7C-BA53-D6AB490A9444"
},
{
"criteria": "cpe:2.3:h:watchguard:firebox_t45:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "DCB1A254-DA3C-4032-B2C6-C9EBCE8EC15E"
},
{
"criteria": "cpe:2.3:h:watchguard:firebox_t55:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "D3562304-0317-4A3C-B622-D5CE01CC97F9"
},
{
"criteria": "cpe:2.3:h:watchguard:firebox_t70:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "327BA50A-366A-4367-93B8-328EC0136FA7"
},
{
"criteria": "cpe:2.3:h:watchguard:firebox_t80:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "D92ABD52-20F6-4AB1-801F-9E7B7B1B78A1"
},
{
"criteria": "cpe:2.3:h:watchguard:firebox_t85:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "3552F3BB-8021-4E87-987D-870699A7E619"
},
{
"criteria": "cpe:2.3:h:watchguard:fireboxcloud:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "158560A0-D694-41AF-A5F8-0F6FB3EFB8FA"
},
{
"criteria": "cpe:2.3:h:watchguard:fireboxv:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "4ECAE1D7-9868-4730-B645-44CB1B6FDE96"
}
],
"operator": "OR"
}
],
"operator": "AND"
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:watchguard:fireware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4D0AAD6D-2794-444D-9866-3E81B1EE2E26",
"versionEndExcluding": "2026.1.2",
"versionStartIncluding": "2025.1"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:h:watchguard:firebox_m295:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "615FF2CF-69DA-4890-9236-52D8D6FA0E71"
},
{
"criteria": "cpe:2.3:h:watchguard:firebox_m395:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "A3439409-2FD6-447B-91CF-17D1C09E2A79"
},
{
"criteria": "cpe:2.3:h:watchguard:firebox_m495:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "C0C0412F-AB02-4D13-B159-D0FCD2ECA3ED"
},
{
"criteria": "cpe:2.3:h:watchguard:firebox_m595:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "575CC5EE-0278-489B-AA95-5EC5058D6FB9"
},
{
"criteria": "cpe:2.3:h:watchguard:firebox_m695:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "5597F672-3C72-4BCF-AD3F-F16B6913EC2F"
},
{
"criteria": "cpe:2.3:h:watchguard:firebox_t115-w:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "E8AAE66B-DD19-4C90-8DFC-F77BA1541642"
},
{
"criteria": "cpe:2.3:h:watchguard:firebox_t125:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "7FC18430-C6B4-4395-BFF1-83BB005875BA"
},
{
"criteria": "cpe:2.3:h:watchguard:firebox_t125-w:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "1A7C1C91-8B6E-4FB0-841E-7F88B06B1435"
},
{
"criteria": "cpe:2.3:h:watchguard:firebox_t145:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "8FE309D6-BD5E-4D18-91C3-A492C3576115"
},
{
"criteria": "cpe:2.3:h:watchguard:firebox_t145-w:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "75959D39-0960-4836-96C7-DB8048DDE4B8"
},
{
"criteria": "cpe:2.3:h:watchguard:firebox_t185:-:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "D0087049-27C6-4B18-A645-72A8F63D7C6D"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"sourceIdentifier": "5d1c2695-1a31-4499-88ae-e847036fd7e3"
}