CVE-2017-8056
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
2Exploited in Wild
-Decision
Descriptions
WatchGuard Fireware v11.12.1 and earlier mishandles requests referring to an XML External Entity (XXE), in the XML-RPC agent. This causes the Firebox wgagent process to crash. This process crash ends all authenticated sessions to the Firebox, including management connections, and prevents new authenticated sessions until the process has recovered. The Firebox may also experience an overall degradation in performance while the wgagent process recovers. An attacker could continuously send XML-RPC requests that contain references to external entities to perform a limited Denial of Service (DoS) attack against an affected Firebox.
WatchGuard Fireware v11.12.1 y solicitudes anteriores de manipulación incorrecta que se refieren a XXE, en el agente XML-RPC. Esto hace que el proceso wgagent de Firebox se bloquee. Este bloqueo de proceso termina todas las sesiones autenticadas en el Firebox, incluidas las conexiones de administración, e impide que se realicen nuevas sesiones autenticadas hasta que el proceso se haya recuperado. El Firebox también puede experimentar una degradación general en el rendimiento mientras se recupera el proceso wgagent. Un atacante podría enviar continuamente solicitudes XML-RPC que contengan referencias a entidades externas para realizar un ataque de Negación de Servicio (DoS) limitado contra un Firebox afectado.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-04-22 CVE Reserved
- 2017-04-22 CVE Published
- 2024-09-17 CVE Updated
- 2024-09-17 EPSS Updated
- 2024-09-17 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-611: Improper Restriction of XML External Entity Reference
CAPEC
References (4)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Watchguard Search vendor "Watchguard" | Fireware Search vendor "Watchguard" for product "Fireware" | <= 11.2.1 Search vendor "Watchguard" for product "Fireware" and version " <= 11.2.1" | - |
Affected
|