← לוח פגיעויות

CVE-2025-0178

בינונית 6.1

תיאור (מקור, אנגלית)

An Improper Input Validation vulnerability in WatchGuard Fireware OS allows an attacker with network access to manipulate the value of the HTTP Host header in requests sent to the Web UI. An attacker could exploit this vulnerability to redirect users to malicious websites, poison the web cache, or inject malicious JavaScript into responses sent by the Web UI.

מדדים

CVSS 3.1
6.1 (MEDIUM) מקור הציון: NVD CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:L/I:L/A:N
CVSS 4.0
5.1 (MEDIUM) מקור הציון: CNA CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:L/SI:L/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS — סבירות ניצול
0% (אחוזון 000) נכון ל-9/10/2026
CWE
CWE-20

מוצרים מושפעים

watchguard: fireware; watchguard: firebox m270; watchguard: firebox m290; watchguard: firebox m370; watchguard: firebox m390; watchguard: firebox m440; watchguard: firebox m4600; watchguard: firebox m470; watchguard: firebox m4800; watchguard: firebox m5600; watchguard: firebox m570; watchguard: firebox m5800; watchguard: firebox m590; watchguard: firebox m670; watchguard: firebox m690

קישורים