CVE-2022-31792
Estado: ModificadaMedia (5.4)—
A stored cross-site scripting (XSS) vulnerability exists in the management web interface of WatchGuard Firebox and XTM appliances. A remote attacker can potentially execute arbitrary JavaScript code in the management web interface by sending crafted requests to exposed management ports. This is fixed in Fireware OS 12.8.1, 12.5.10, and 12.1.4.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N
- Puntuación base: 5.4
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.59%
- Percentil entre todas las CVEs puntuadas: 47
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-79
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2022-31792",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "CHANGED",
"version": "3.1",
"baseScore": 5.4,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N",
"integrityImpact": "LOW",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "NONE",
"privilegesRequired": "LOW",
"confidentialityImpact": "LOW"
},
"impactScore": 2.7,
"exploitabilityScore": 2.3
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2022-09-06T19:15:08.440",
"references": [
{
"url": "https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2022-00014",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2022-00014",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-79"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "A stored cross-site scripting (XSS) vulnerability exists in the management web interface of WatchGuard Firebox and XTM appliances. A remote attacker can potentially execute arbitrary JavaScript code in the management web interface by sending crafted requests to exposed management ports. This is fixed in Fireware OS 12.8.1, 12.5.10, and 12.1.4."
},
{
"lang": "es",
"value": "Se presenta una vulnerabilidad de tipo cross-site scripting (XSS) almacenado en la interfaz web de administración de los dispositivos WatchGuard Firebox y XTM. Un atacante remoto puede potencialmente ejecutar código JavaScript arbitrario en la interfaz web de administración mediante el envío de peticiones diseñadas a los puertos de administración expuestos. Esto ha sido corregido en Fireware OS versiones 12.8.1, 12.5.10 y 12.1.4.\n"
}
],
"lastModified": "2026-06-17T04:46:19.007",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:watchguard:fireware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "50E35898-20FC-4D3E-B059-EDFEEB2E19F3",
"versionEndExcluding": "12.1.4",
"versionStartIncluding": "12.0.0"
},
{
"criteria": "cpe:2.3:o:watchguard:fireware:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "58A5359B-EC12-4C13-B9CC-EE1B49DB67AE",
"versionEndExcluding": "12.5.10",
"versionStartIncluding": "12.2.0"
},
{
"criteria": "cpe:2.3:o:watchguard:fireware:12.6.1:u1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2EDC1E95-9077-423E-90F4-928068CA6D74"
},
{
"criteria": "cpe:2.3:o:watchguard:fireware:12.6.1:u3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C557A092-41F2-4325-884C-B4C03E196A56"
},
{
"criteria": "cpe:2.3:o:watchguard:fireware:12.6.3:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "41CE5E56-7E6E-48ED-A619-06BE1DAAABD2"
},
{
"criteria": "cpe:2.3:o:watchguard:fireware:12.6.4:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "299FC710-1AA1-4D3F-B902-231114B75B94"
},
{
"criteria": "cpe:2.3:o:watchguard:fireware:12.7.0:u1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "45C56536-625E-4E5A-B77A-CF33CEEBC91D"
},
{
"criteria": "cpe:2.3:o:watchguard:fireware:12.7.1:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "002B43DA-5A94-495D-8736-2FC5997155F9"
},
{
"criteria": "cpe:2.3:o:watchguard:fireware:12.7.2:u2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4B189948-8037-4CB1-A859-0CCB5D9576F8"
},
{
"criteria": "cpe:2.3:o:watchguard:fireware:12.8.0:u1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "350B4BC0-B366-468B-93BF-366CA72EE5EC"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "cve@mitre.org"
}