CISA: WatchGuard RCE flaw now exploited in ransomware attacks
Summary
CISA has confirmed that ransomware groups are actively exploiting a critical remote code execution (RCE) vulnerability in WatchGuard Firebox firewalls. This flaw was initially flagged by CISA as actively exploited in December.
IFF Assessment
The exploitation of a critical vulnerability in widely used security devices by ransomware gangs poses a direct threat to organizations and their data.
Severity
The CVSS score is estimated to be high (9.8) due to the critical nature of a remote code execution vulnerability in a firewall, which allows for widespread compromise and potential network control, likely with a high attack vector and significant impact.
Defender Context
Defenders should prioritize patching or mitigating the WatchGuard Firebox RCE vulnerability immediately, as it is being actively exploited by ransomware groups. This incident highlights the importance of keeping network perimeter devices up-to-date and monitoring for signs of exploitation.