Watchguard

Fireware

80 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Medienbericht
  • EPSS 0.42%
  • Veröffentlicht 30.09.2026 03:37:57
  • Zuletzt bearbeitet 06.10.2026 17:30:29

A NULL pointer dereference vulnerability in the WatchGuard Fireware OS authentication process allows a remote, unauthenticated attacker to crash the management daemon by sending a specially request to the login interface, resulting in a denial of ser...

Medienbericht
  • EPSS 0.36%
  • Veröffentlicht 29.09.2026 23:05:48
  • Zuletzt bearbeitet 06.10.2026 20:49:44

An uncontrolled resource consumption vulnerability in the Fireware OS login process (wgagent) allows a remote, unauthenticated attacker to cause a denial of service by sending a specially crafted request.

Medienbericht
  • EPSS 0.21%
  • Veröffentlicht 29.09.2026 23:05:47
  • Zuletzt bearbeitet 06.10.2026 20:02:48

A missing authorization vulnerability in the wgagent management daemon's session initialization function allows an authenticated, low-privileged user (including a read-only or guest administrator account) to crash the wgagent process and read arbitra...

Medienbericht
  • EPSS 0.27%
  • Veröffentlicht 29.09.2026 23:05:47
  • Zuletzt bearbeitet 06.10.2026 20:22:36

A missing authorization vulnerability in the wgagent management daemon's session initialization function allows an authenticated, low-privileged user (including a read-only or guest administrator account) to crash the wgagent process and read arbitra...

Medienbericht
  • EPSS 0.34%
  • Veröffentlicht 29.09.2026 23:05:47
  • Zuletzt bearbeitet 06.10.2026 20:28:50

An integer underflow vulnerability in the WatchGuard Fireware OS IKE daemon (iked) allows a remote attacker who has completed the initial IKEv2 handshake to crash the iked process by sending a specially crafted encrypted IKEv2 message, resulting in a...

Medienbericht
  • EPSS 0.36%
  • Veröffentlicht 29.09.2026 23:05:47
  • Zuletzt bearbeitet 06.10.2026 20:36:46

An integer underflow vulnerability in the WatchGuard Fireware OS IKEv2 daemon (iked) allows a remote, unauthenticated attacker to crash the process by sending a specially crafted encrypted IKEv2 message negotiated with an AES-GCM cipher suite.

Medienbericht
  • EPSS 0.33%
  • Veröffentlicht 29.09.2026 23:05:47
  • Zuletzt bearbeitet 06.10.2026 20:39:54

A code injection vulnerability in WatchGuard Fireware OS's BOVPN Over TLS client configuration handling allows an attacker who controls the remote VPN server to execute arbitrary commands as root on the connecting Firebox.

Medienbericht
  • EPSS 0.36%
  • Veröffentlicht 29.09.2026 23:05:47
  • Zuletzt bearbeitet 06.10.2026 20:42:54

A NULL pointer dereference vulnerability in Fireware OS's NetFlow packet-processing feature allows a remote, unauthenticated attacker to cause a denial of service by sending a specially crafted IPv6 packet.

Medienbericht
  • EPSS 0.36%
  • Veröffentlicht 29.09.2026 23:05:47
  • Zuletzt bearbeitet 06.10.2026 20:47:02

An improper authorization vulnerability in Fireware OS's Access Portal reverse proxy allows an authenticated, low-privileged Access Portal user to access other web applications they are not authorized for by sending a specially crafted request for a ...

Medienbericht
  • EPSS 0.2%
  • Veröffentlicht 29.09.2026 23:05:47
  • Zuletzt bearbeitet 01.10.2026 04:18:20

A stack-based buffer overflow vulnerability in WatchGuard Fireware OS's DHCP fingerprinting daemon (fingerd) allows an unauthenticated attacker with adjacent network access to execute arbitrary code or crash the process by sending a specially crafted...