Watchguard

Fireware

46 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
Exploit
  • EPSS 0.36%
  • Veröffentlicht 20.09.2017 20:29:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

An FBX-5313 issue was discovered in WatchGuard Fireware before 12.0. When a failed login attempt is made to the login endpoint of the XML-RPC interface, if JavaScript code, properly encoded to be consumed by XML parsers, is embedded as value of the u...

Exploit
  • EPSS 16.31%
  • Veröffentlicht 22.04.2017 22:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

WatchGuard Fireware v11.12.1 and earlier mishandles requests referring to an XML External Entity (XXE), in the XML-RPC agent. This causes the Firebox wgagent process to crash. This process crash ends all authenticated sessions to the Firebox, includi...

Exploit
  • EPSS 0.29%
  • Veröffentlicht 22.04.2017 22:59:00
  • Zuletzt bearbeitet 20.04.2025 01:37:25

WatchGuard Fireware allows user enumeration, e.g., in the Firebox XML-RPC login handler. A login request that contains a blank password sent to the XML-RPC agent in Fireware v11.12.1 and earlier returns different responses for valid and invalid usern...

Exploit
  • EPSS 2.15%
  • Veröffentlicht 16.03.2014 14:06:45
  • Zuletzt bearbeitet 12.04.2025 10:46:40

Multiple cross-site scripting (XSS) vulnerabilities in the firewall policy management pages in WatchGuard Fireware XTM before 11.8.3 allow remote attackers to inject arbitrary web script or HTML via the pol_name parameter.

  • EPSS 0.26%
  • Veröffentlicht 19.10.2013 10:36:08
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Multiple cross-site scripting (XSS) vulnerabilities in WebCenter in WatchGuard WSM and Fireware before 11.8 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters.

Exploit
  • EPSS 54.04%
  • Veröffentlicht 19.10.2013 10:36:08
  • Zuletzt bearbeitet 11.04.2025 00:51:21

Buffer overflow in WGagent in WatchGuard WSM and Fireware before 11.8 allows remote attackers to execute arbitrary code via a long sessionid value in a cookie.