Watchguard

Fireware

31 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 1.92%
  • Veröffentlicht 24.02.2022 15:15:31
  • Zuletzt bearbeitet 21.11.2024 06:51:56

An integer overflow in WatchGuard Firebox and XTM appliances allows an authenticated remote attacker to trigger a heap-based buffer overflow and potentially execute arbitrary code by initiating a firmware update with a malicious upgrade image. This v...

  • EPSS 0.14%
  • Veröffentlicht 24.02.2022 15:15:30
  • Zuletzt bearbeitet 21.11.2024 06:51:56

WatchGuard Firebox and XTM appliances allow an authenticated remote attacker with unprivileged credentials to retrieve certificate private keys. This vulnerability impacts Fireware OS before 12.7.2_U2, 12.x before 12.1.3_U8, and 12.2.x through 12.5.x...

Warnung
  • EPSS 6.96%
  • Veröffentlicht 24.02.2022 15:15:28
  • Zuletzt bearbeitet 14.03.2025 16:50:46

WatchGuard Firebox and XTM appliances allow a remote attacker with unprivileged credentials to access the system with a privileged management session via exposed management access. This vulnerability impacts Fireware OS before 12.7.2_U1, 12.x before ...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 23.08.2019 22:15:11
  • Zuletzt bearbeitet 21.11.2024 02:55:33

The authentication applet in Watchguard Fireware 11.11 Operating System has reflected XSS (this can also cause an open redirect).

Exploit
  • EPSS 0.83%
  • Veröffentlicht 20.09.2017 20:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

An FBX-5312 issue was discovered in WatchGuard Fireware before 12.0. If a login attempt is made in the XML-RPC interface with an XML message containing an empty member element, the wgagent crashes, logging out any user with a session opened in the UI...

Exploit
  • EPSS 0.36%
  • Veröffentlicht 20.09.2017 20:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

An FBX-5313 issue was discovered in WatchGuard Fireware before 12.0. When a failed login attempt is made to the login endpoint of the XML-RPC interface, if JavaScript code, properly encoded to be consumed by XML parsers, is embedded as value of the u...

Exploit
  • EPSS 16.31%
  • Veröffentlicht 22.04.2017 22:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

WatchGuard Fireware v11.12.1 and earlier mishandles requests referring to an XML External Entity (XXE), in the XML-RPC agent. This causes the Firebox wgagent process to crash. This process crash ends all authenticated sessions to the Firebox, includi...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 22.04.2017 22:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

WatchGuard Fireware allows user enumeration, e.g., in the Firebox XML-RPC login handler. A login request that contains a blank password sent to the XML-RPC agent in Fireware v11.12.1 and earlier returns different responses for valid and invalid usern...

Exploit
  • EPSS 2.15%
  • Veröffentlicht 16.03.2014 14:06:45
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple cross-site scripting (XSS) vulnerabilities in the firewall policy management pages in WatchGuard Fireware XTM before 11.8.3 allow remote attackers to inject arbitrary web script or HTML via the pol_name parameter.

  • EPSS 0.26%
  • Veröffentlicht 19.10.2013 10:36:08
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Multiple cross-site scripting (XSS) vulnerabilities in WebCenter in WatchGuard WSM and Fireware before 11.8 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters.