WGSA-2021-00001#
WatchGuard Firebox Privilege Escalation Vulnerability
Summary #
*Updated September 5 2025: Updated to clarify Fireware OS 12.3.1 Update 2 (FIPS-certified release) resolves this issue*
Firebox and XTM appliances have a privilege escalation vulnerability that could allow an authenticated management user with Device Monitor permissions to execute management commands and access Firebox resources as a Device Management user.
CVE identifiers #
No CVE identifiers are associated with this advisory.
Product status #
| Product | Affected | Not affected |
|---|---|---|
| Fireware OS | ||
| Default | >= 12.0, < 12.7.1 | >= 12.7.1 |
| T15/T35 | >= 12.5.0, < 12.5.8 | >= 12.5.8 |
| FIPS | >= 12.3.1, < 12.3.1-B675192 | >= 12.3.1-B675192 |
Solution #
Fireware OS 12.7.1, Fireware OS 12.5.8, Fireware OS 12.3.1-B675192