Search: "watchguard"

102 CVEs found

CVE-2011-2165
6.8 MEDIUM

The STARTTLS implementation in WatchGuard XCS 9.0 and 9.1 does not properly restrict I/O buffering, which allows man-in-the-middle attackers to insert commands into encrypted SMTP sessions by sending ...

Published: 2011-05-23
Products: 2
Vendors:
watchguard

Multiple untrusted search path vulnerabilities in (1) Watchguard Log Collector (wlcollector.exe) and (2) Watchguard WebBlocker Server (wbserver.exe) in WatchGuard Server Center 11.7.4, 11.7.3, and pos...

Published: 2013-10-03
Products: 2
Vendors:
watchguard
CVE-2013-5702
4.3 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in WebCenter in WatchGuard WSM and Fireware before 11.8 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters.

Published: 2013-10-19
Products: 10
Vendors:
watchguard

Buffer overflow in WGagent in WatchGuard WSM and Fireware before 11.8 allows remote attackers to execute arbitrary code via a long sessionid value in a cookie.

Published: 2013-10-19
Products: 12
Vendors:
watchguard
CVE-2014-0338
4.3 MEDIUM

Multiple cross-site scripting (XSS) vulnerabilities in the firewall policy management pages in WatchGuard Fireware XTM before 11.8.3 allow remote attackers to inject arbitrary web script or HTML via t...

Published: 2014-03-16
Products: 11
Vendors:
watchguard

SQL injection vulnerability in Watchguard XCS 9.2 and 10.0 before build 150522 allows remote attackers to execute arbitrary SQL commands via the sid cookie, as demonstrated by a request to borderpost/...

Published: 2015-07-08
Products: 2
Vendors:
watchguard
CVE-2015-5453
6.5 MEDIUM

Watchguard XCS 9.2 and 10.0 before build 150522 allow remote authenticated users to execute arbitrary commands via shell metacharacters in the id parameter to ADMIN/mailqueue.spl.

Published: 2015-07-08
Products: 2
Vendors:
watchguard

WatchGuard RapidStream appliances allow local users to gain privileges and execute arbitrary commands via a crafted ifconfig command, aka ESCALATEPLOWMAN.

Published: 2016-08-24
Products: 1
Vendors:
watchguard
CVE-2017-8055
5.3 MEDIUM

WatchGuard Fireware allows user enumeration, e.g., in the Firebox XML-RPC login handler. A login request that contains a blank password sent to the XML-RPC agent in Fireware v11.12.1 and earlier retur...

Published: 2017-04-22
Products: 1
Vendors:
watchguard
CVE-2017-8056
5.3 MEDIUM

WatchGuard Fireware v11.12.1 and earlier mishandles requests referring to an XML External Entity (XXE), in the XML-RPC agent. This causes the Firebox wgagent process to crash. This process crash ends ...

Published: 2017-04-22
Products: 1
Vendors:
watchguard
CVE-2017-14615
6.1 MEDIUM

An FBX-5313 issue was discovered in WatchGuard Fireware before 12.0. When a failed login attempt is made to the login endpoint of the XML-RPC interface, if JavaScript code, properly encoded to be cons...

Published: 2017-09-20
Products: 1
Vendors:
watchguard

An FBX-5312 issue was discovered in WatchGuard Fireware before 12.0. If a login attempt is made in the XML-RPC interface with an XML message containing an empty member element, the wgagent crashes, lo...

Published: 2017-09-20
Products: 1
Vendors:
watchguard
CVE-2018-10575
9.8 CRITICAL

An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15. Hardcoded credentials exist for an unprivileged SSH account with a shell of /bin/false.

Published: 2018-04-30
Products: 6
Vendors:
watchguard

An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15. Improper authentication handling by the native Access Point web UI allows authentication using a lo...

Published: 2018-04-30
Products: 6
Vendors:
watchguard

An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15, and AP300 devices with firmware before 2.0.0.10. File upload functionality allows any users authent...

Published: 2018-05-02
Products: 8
Vendors:
watchguard
CVE-2018-10578
9.8 CRITICAL

An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15, and AP300 devices with firmware before 2.0.0.10. Incorrect validation of the "old password" field i...

Published: 2018-05-02
Products: 8
Vendors:
watchguard
CVE-2016-6154
6.1 MEDIUM

The authentication applet in Watchguard Fireware 11.11 Operating System has reflected XSS (this can also cause an open redirect).

Published: 2019-08-23
Products: 2
Vendors:
microsoft watchguard
CVE-2019-18652
6.1 MEDIUM

A DOM based XSS vulnerability has been identified on the WatchGuard XMT515 through 12.1.3, allowing a remote attacker to execute JavaScript in the victim's browser by tricking the victim into clicking...

Published: 2020-01-07
Products: 2
Vendors:
watchguard
CVE-2014-6413
6.1 MEDIUM

A Cross-site Scripting (XSS) vulnerability exists in WatchGuard XTM 11.8.3 via the poll_name parameter in the firewall/policy script.

Published: 2020-02-07
Products: 1
Vendors:
watchguard

The AD Helper component in WatchGuard Fireware before 5.8.5.10317 allows remote attackers to discover cleartext passwords via the /domains/list URI.

Published: 2020-03-12
Products: 1
Vendors:
watchguard