← לוח פגיעויות

CVE-2026-13728

בינונית 4.4

תיאור (מקור, אנגלית)

In exception circumstances, WatchGuard Fireware OS on a FireCluster may use a hard-coded encryption key to encrypt saved credentials for Access Portal resources. This vulnerability does not affect devices that do not support the Access Portal feature or standalone Fireboxes not deployed in a FireCluster.

מדדים

CVSS 3.1
4.4 (MEDIUM) מקור הציון: NVD CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:N/A:N
CVSS 4.0
5.9 (MEDIUM) מקור הציון: CNA CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS — סבירות ניצול
0% (אחוזון 000) נכון ל-15/8/2026
CWE
CWE-798

מוצרים מושפעים

watchguard: fireware; watchguard: firebox m270; watchguard: firebox m290; watchguard: firebox m370; watchguard: firebox m390; watchguard: firebox m440; watchguard: firebox m4600; watchguard: firebox m470; watchguard: firebox m4800; watchguard: firebox m5600; watchguard: firebox m570; watchguard: firebox m5800; watchguard: firebox m590; watchguard: firebox m670; watchguard: firebox m690

קישורים