Watchguard

Fireware

69 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.45%
  • Veröffentlicht 15.09.2025 21:17:51
  • Zuletzt bearbeitet 10.08.2026 16:19:28

An HTTP Request Smuggling [CWE-444] vulnerability in the Authentication portal of WatchGuard Fireware OS allows a remote attacker to evade request parameter sanitation and perform a reflected self-Cross-Site Scripting (XSS) attack. WatchGuard does n...

  • EPSS 0.54%
  • Veröffentlicht 16.05.2025 20:13:47
  • Zuletzt bearbeitet 08.08.2026 03:16:44

A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the Access Portal configuration. An authenticated remote attacker with administrator privileges could exploit this vulnerability...

  • EPSS 0.45%
  • Veröffentlicht 16.05.2025 20:12:44
  • Zuletzt bearbeitet 08.08.2026 03:16:44

Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in WatchGuard Fireware OS allows Stored XSS via the spamBlocker module. This vulnerability requires an authenticated administrator session to a ...

  • EPSS 0.54%
  • Veröffentlicht 14.02.2025 14:15:32
  • Zuletzt bearbeitet 08.08.2026 03:16:43

A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the Blocked Sites list. An authenticated remote attacker with administrator privileges could exploit this vulnerability to execu...

  • EPSS 0.3%
  • Veröffentlicht 14.02.2025 14:15:32
  • Zuletzt bearbeitet 08.08.2026 00:16:33

A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the spamBlocker module. An authenticated remote attacker with administrator privileges could exploit this vulnerability to execu...

  • EPSS 0.23%
  • Veröffentlicht 14.02.2025 14:15:32
  • Zuletzt bearbeitet 08.08.2026 03:16:43

An Improper Input Validation vulnerability in WatchGuard Fireware OS allows an attacker with network access to manipulate the value of the HTTP Host header in requests sent to the Web UI. An attacker could exploit this vulnerability to redirect users...

  • EPSS 1.26%
  • Veröffentlicht 28.01.2025 00:15:06
  • Zuletzt bearbeitet 15.04.2026 00:35:42

An argument injection vulnerability in the diagnose and import pac commands in WatchGuard Fireware OS before 12.8.1, 12.1.4, and 12.5.10 allows an authenticated remote attacker with unprivileged credentials to upload or read files to limited, arbitra...

  • EPSS 0.97%
  • Veröffentlicht 09.07.2024 03:15:02
  • Zuletzt bearbeitet 07.08.2026 22:16:56

A buffer overflow in WatchGuard Fireware OS could may allow an authenticated remote attacker with privileged management access to execute arbitrary code with system privileges on the firewall. This issue affects Fireware OS: from 11.9.6 through 12.10...

  • EPSS 0.52%
  • Veröffentlicht 06.09.2022 19:15:08
  • Zuletzt bearbeitet 21.11.2024 07:05:20

A stored cross-site scripting (XSS) vulnerability exists in the management web interface of WatchGuard Firebox and XTM appliances. A remote attacker can potentially execute arbitrary JavaScript code in the management web interface by sending crafted ...

  • EPSS 0.22%
  • Veröffentlicht 06.09.2022 19:15:08
  • Zuletzt bearbeitet 21.11.2024 07:05:19

WatchGuard Firebox and XTM appliances allow a local attacker (that has already obtained shell access) to elevate their privileges and execute code with root permissions. This is fixed in Fireware OS 12.8.1, 12.5.10, and 12.1.4.