important · Edge — VPN
A malicious BOVPN over TLS server can execute commands as root on a connecting Firebox.
Affects
WatchGuard Firebox network-security appliances running Fireware OS and configured as BOVPN over TLS clients.
The Firebox must already be configured to connect to the attacker-controlled server; improper certificate validation and code injection then turn server-supplied configuration into root commands.