{"$schema":"https://docs.oasis-open.org/csaf/csaf/v2.1/schema/csaf.json","document":{"category":"csaf_security_advisory","csaf_version":"2.1","title":"WatchGuard Firebox Privilege Escalation Vulnerability","distribution":{"tlp":{"label":"CLEAR"}},"publisher":{"category":"vendor","name":"WatchGuard PSIRT","namespace":"https://www.watchguard.com"},"tracking":{"id":"WGSA-2021-00001","status":"final","version":"22","initial_release_date":"2021-08-02T10:00:00+00:00","current_release_date":"2026-07-27T17:20:57.347347+00:00","revision_history":[{"date":"2021-08-02T10:00:00+00:00","number":"22","summary":"Initial release."}]},"references":[{"summary":"vendor-advisory","url":"https://psirt.watchguard.com/WGSA-2021-00001"}],"notes":[{"category":"summary","text":"*Updated September 5 2025: Updated to clarify Fireware OS 12.3.1 Update 2 (FIPS-certified release) resolves this issue*\n\nFirebox and XTM appliances have a privilege escalation vulnerability that could allow an authenticated management user with Device Monitor permissions to execute management commands and access Firebox resources as a Device Management user.","title":"Summary"}]},"product_tree":{"branches":[{"category":"vendor","name":"WatchGuard","branches":[{"category":"product_name","name":"Fireware OS (Default)","branches":[{"category":"product_version_range","name":"vers >= 12.0, < 12.7.1","product":{"name":"Fireware OS (Default) vers >= 12.0, < 12.7.1","product_id":"CSAFPID-46ae0b14-8bdb-41f9-a57b-563a6e76c5c7-default"}}]},{"category":"product_name","name":"Fireware OS (FIPS)","branches":[{"category":"product_version_range","name":"vers >= 12.3.1, < 12.3.1-B675192","product":{"name":"Fireware OS (FIPS) vers >= 12.3.1, < 12.3.1-B675192","product_id":"CSAFPID-46ae0b14-8bdb-41f9-a57b-563a6e76c5c7-fips"}}]},{"category":"product_name","name":"Fireware OS (T15/T35)","branches":[{"category":"product_version_range","name":"vers >= 12.5.0, < 12.5.8","product":{"name":"Fireware OS (T15/T35) vers >= 12.5.0, < 12.5.8","product_id":"CSAFPID-46ae0b14-8bdb-41f9-a57b-563a6e76c5c7-t15/t35"}}]}]}]},"vulnerabilities":[{"notes":[{"category":"description","text":"*Updated September 5 2025: Updated to clarify Fireware OS 12.3.1 Update 2 (FIPS-certified release) resolves this issue*\n\nFirebox and XTM appliances have a privilege escalation vulnerability that could allow an authenticated management user with Device Monitor permissions to execute management commands and access Firebox resources as a Device Management user.","title":"Summary"}],"product_status":{"known_affected":["CSAFPID-46ae0b14-8bdb-41f9-a57b-563a6e76c5c7-default","CSAFPID-46ae0b14-8bdb-41f9-a57b-563a6e76c5c7-fips","CSAFPID-46ae0b14-8bdb-41f9-a57b-563a6e76c5c7-t15/t35"]},"remediations":[{"category":"vendor_fix","details":"Upgrade to Fireware OS 12.3.1-B675192 or later.","product_ids":["CSAFPID-46ae0b14-8bdb-41f9-a57b-563a6e76c5c7-fips"]},{"category":"vendor_fix","details":"Upgrade to Fireware OS 12.5.8 or later.","product_ids":["CSAFPID-46ae0b14-8bdb-41f9-a57b-563a6e76c5c7-t15/t35"]},{"category":"vendor_fix","details":"Upgrade to Fireware OS 12.7.1 or later.","product_ids":["CSAFPID-46ae0b14-8bdb-41f9-a57b-563a6e76c5c7-default"]}]}]}