Vulnerability index

Browse CVEs

98 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Fireware Xtm MEDIUM 6.1
CVE-2014-6413

A Cross-site Scripting (XSS) vulnerability exists in WatchGuard XTM 11.8.3 via the poll_name parameter in the firewall/policy script.

No fix yet
Fix from $1,600 2020-02-07
Xmt515 Firmware MEDIUM 6.1
CVE-2019-18652

A DOM based XSS vulnerability has been identified on the WatchGuard XMT515 through 12.1.3, allowing a remote attacker to execute JavaScript in the vi…

Fix: after 12.3
Fix from $1,600 2020-01-07
Fireware MEDIUM 6.1
CVE-2016-6154

The authentication applet in Watchguard Fireware 11.11 Operating System has reflected XSS (this can also cause an open redirect).

Fix: after 11.11
Fix from $1,600 2019-08-23
Ap200 Firmware CRITICAL 9.8
CVE-2018-10578

An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15, and AP300 devices with firmware before 2.0.0.10.…

Fix: 1.2.9.15 / 2.0.0.10+
Fix from $2,300 2018-05-02
Ap200 Firmware HIGH 8.8
CVE-2018-10577EPSS 7%

An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15, and AP300 devices with firmware before 2.0.0.10.…

Fix: 1.2.9.15 / 2.0.0.10+
Fix from $1,950 2018-05-02
Ap200 Firmware CRITICAL 9.8
CVE-2018-10575EPSS 9%

An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15. Hardcoded credentials exist for an unprivileged …

Fix: 1.2.9.15+
Fix from $2,300 2018-04-30
Ap200 Firmware HIGH 7.8
CVE-2018-10576

An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15. Improper authentication handling by the native A…

Fix: 1.2.9.15+
Fix from $1,950 2018-04-30
Hawkeye G HIGH 8.8
CVE-2015-2878

Multiple cross-site request forgery (CSRF) vulnerabilities in Hexis HawkEye G 3.0.1.4912 allow remote attackers to hijack the authentication of admin…

No fix yet
Fix from $1,950 2017-10-23
Fireware HIGH 7.5
CVE-2017-14616

An FBX-5312 issue was discovered in WatchGuard Fireware before 12.0. If a login attempt is made in the XML-RPC interface with an XML message containi…

Fix: after 11.12.4
Fix from $1,950 2017-09-20
Fireware MEDIUM 6.1
CVE-2017-14615

An FBX-5313 issue was discovered in WatchGuard Fireware before 12.0. When a failed login attempt is made to the login endpoint of the XML-RPC interfa…

Fix: after 11.12.4
Fix from $1,600 2017-09-20
Panda Mobile Security MEDIUM 5.9
CVE-2017-8060

Acceptance of invalid/self-signed TLS certificates in "Panda Mobile Security" 1.1 for iOS allows a man-in-the-middle and/or physically proximate atta…

Mitigation only
Fix from $1,600 2017-05-05
Panda Antivirus MEDIUM 5.5
CVE-2017-8339

PSKMAD.sys in Panda Free Antivirus 18.0 allows local users to cause a denial of service (BSoD) via a crafted DeviceIoControl request to \\.\PSMEMDriv…

No fix yet
Fix from $1,600 2017-04-30
Fireware MEDIUM 5.3
CVE-2017-8055

WatchGuard Fireware allows user enumeration, e.g., in the Firebox XML-RPC login handler. A login request that contains a blank password sent to the X…

Fix: after 11.2.1
Fix from $1,600 2017-04-22
Fireware MEDIUM 5.3
CVE-2017-8056EPSS 5%

WatchGuard Fireware v11.12.1 and earlier mishandles requests referring to an XML External Entity (XXE), in the XML-RPC agent. This causes the Firebox…

Fix: after 11.2.1
Fix from $1,600 2017-04-22
Rapidstream HIGH 7.8
CVE-2016-7089

WatchGuard RapidStream appliances allow local users to gain privileges and execute arbitrary commands via a crafted ifconfig command, aka ESCALATEPLO…

No fix yet
Fix from $1,950 2016-08-24
Panda Endpoint Administration Agent HIGH 7.8
CVE-2016-3943

Panda Endpoint Administration Agent before 7.50.00, as used in Panda Security for Business products for Windows, uses a weak ACL for the Panda Securi…

Fix: after 7.49
Fix from $1,950 2016-04-18
Panda Url Filtering HIGH 7.8
CVE-2015-7378

Panda Security URL Filtering before 4.3.1.9 uses a weak ACL for the "Panda Security URL Filtering" directory and installed files, which allows local …

Fix: after 4.3.1.8
Fix from $1,950 2016-04-18
Xcs MEDIUM 6.5
CVE-2015-5453EPSS 57%

Watchguard XCS 9.2 and 10.0 before build 150522 allow remote authenticated users to execute arbitrary commands via shell metacharacters in the id par…

No fix yet
Fix from $1,600 2015-07-08
Xcs HIGH 7.5
CVE-2015-5452

SQL injection vulnerability in Watchguard XCS 9.2 and 10.0 before build 150522 allows remote attackers to execute arbitrary SQL commands via the sid …

No fix yet
Fix from $1,950 2015-07-08
Fireware HIGH 9.3
CVE-2013-6021EPSS 12%

Buffer overflow in WGagent in WatchGuard WSM and Fireware before 11.8 allows remote attackers to execute arbitrary code via a long sessionid value in…

Fix: after 11.7.4
Fix from $1,950 2013-10-19
Server Center HIGH 7.2
CVE-2013-5701

Multiple untrusted search path vulnerabilities in (1) Watchguard Log Collector (wlcollector.exe) and (2) Watchguard WebBlocker Server (wbserver.exe) …

Fix: after 11.7.4
Fix from $1,950 2013-10-03
Xcs MEDIUM 6.8
CVE-2011-2165EPSS 5%

The STARTTLS implementation in WatchGuard XCS 9.0 and 9.1 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to inser…

Mitigation only
Fix from $1,600 2011-05-23
Firebox Pptp Vpn MEDIUM 5.0
CVE-2008-1618

The PPTP VPN service in Watchguard Firebox before 10, when performing the MS-CHAPv2 authentication handshake, generates different error codes dependi…

Patch available
Fix from $1,600 2008-04-07
Legacy Rssa HIGH 7.5
CVE-2002-1979

WatchGuard SOHO products running firmware 5.1.6 and earlier, and Vclass/RSSA using 3.2 SP1 and earlier, allows remote attackers to bypass firewall ru…

Fix: after 5.1.6
Fix from $1,950 2002-12-31
Soho Firewall HIGH 7.5
CVE-2002-1047

The FTP service in Watchguard Soho Firewall 5.0.35a allows remote attackers to gain privileges with a correct password but an incorrect user name.

Mitigation only
Fix from $1,950 2002-10-04
Firebox MEDIUM 5.0
CVE-2002-1046

Dynamic VPN Configuration Protocol service (DVCP) in Watchguard Firebox firmware 5.x.x allows remote attackers to cause a denial of service (crash) v…

Patch available
Fix from $1,600 2002-10-04
Soho Firewall HIGH 10.0
CVE-2002-0528

Watchguard SOHO firewall 5.0.35 unpredictably disables certain IP restrictions for customized services that were set before the administrator upgrade…

Patch available
Fix from $1,950 2002-08-12
Soho Firewall MEDIUM 5.0
CVE-2002-0527

Watchguard SOHO firewall before 5.0.35 allows remote attackers to cause a denial of service (crash and reboot) when SOHO forwards a packet with bad I…

Patch available
Fix from $1,600 2002-08-12
Firebox 2500 HIGH 7.5
CVE-2001-0692

SMTP proxy in WatchGuard Firebox (2500 and 4500) 4.5 and 4.6 allows a remote attacker to bypass firewall filtering via a base64 MIME encoded email at…

Patch available
Fix from $1,950 2001-09-20
Firebox Ii MEDIUM 5.0
CVE-2001-0592

Watchguard Firebox II prior to 4.6 allows a remote attacker to create a denial of service in the kernel via a large stream (>10,000) of malformed ICM…

Fix: after 4.6
Fix from $1,600 2001-08-02