Watchguard
watchguard
115 CVEs • 115 products
Products (115)
Click to collapseToggle
Products (115)
Click to collapse
CVEs (115)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A memory corruption vulnerability in WatchGuard Fireware OS may allow an unauthenticated attacker to trigger a Denial of Service (DoS) condition in the Mobile User VPN with IKEv2 and the Branch Office VPN using IKEv2 whe...Show more |
An Out-of-bounds Write vulnerability in the WatchGuard Fireware OS iked process may allow a remote unauthenticated attacker to execute arbitrary code. This vulnerability affects both the mobile user VPN with IKEv2 and th...Show more |
A stored cross-site scripting (XSS) vulnerability exists in the management interface of WatchGuard Firebox appliances via the spamBlocker module. An authenticated remote attacker with administrator privileges could explo...Show more |
An Improper Input Validation vulnerability in WatchGuard Fireware OS allows an attacker with network access to manipulate the value of the HTTP Host header in requests sent to the Web UI. An attacker could exploit this v...Show more |
Panda Security Dome Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Panda Security Dome. An attacker must first obtai...Show more |
1Watchguard 1Single Sign On Client Aug 8, 2026 Sep 25, 2024 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 Improper Handling of Exceptional Conditions vulnerability in the WatchGuard Single Sign-On Client on Windows causes the client to crash while handling malformed commands. An attacker with network access to the client cou...Show more |
1Watchguard 1Authentication Gateway Aug 8, 2026 Sep 25, 2024 9.3 CRITICAL· v4 9.1 CRITICAL· v3 N/A· v2 Incorrect Authorization vulnerability in WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows allows an attacker with network access to execute restricted management commands. An attacker that has alr...Show more |
1Watchguard 2Authentication Gateway Single Sign On ClientAug 8, 2026 Sep 25, 2024 9.3 CRITICAL· v4 9.1 CRITICAL· v3 N/A· v2 An incorrect authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows and the WatchGuard Single Sign-On Client on Windows and MacOS all...Show more |
A buffer overflow in WatchGuard Fireware OS could may allow an authenticated remote attacker with privileged management access to execute arbitrary code with system privileges on the firewall. This issue affects Fireware...Show more |
A local privilege escalation vlnerability in the WatchGuard Mobile VPN with SSL client on Windows enables a local user to execute arbitrary commands with elevated privileged. |
7Cisco CitrixF5+4 more9Anyconnect Vpn Client Big Ip Access Policy ManagerClient Connector+6 moreJun 17, 2026 May 6, 2024 N/A· v4 7.6 HIGH· v3 N/A· v2 DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface....Show more |
1Watchguard 4Edr Firmware Epdr FirmwareEpp Firmware+1 moreJun 17, 2026 Oct 5, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 An issue was discovered in WatchGuard EPDR 8.0.21.0002. Due to a weak implementation of a password check, it is possible to obtain credentials to access the management console as a non-privileged user. |
1Watchguard 4Edr Firmware Epdr FirmwareEpp Firmware+1 moreJun 17, 2026 Oct 5, 2023 N/A· v4 5.5 MEDIUM· v3 N/A· v2 An issue was discovered in WatchGuard EPDR 8.0.21.0002. It is possible to enable or disable defensive capabilities by sending a crafted message to a named pipe. |
1Watchguard 4Edr Firmware Epdr FirmwareEpp Firmware+1 moreJun 17, 2026 Oct 5, 2023 N/A· v4 6.7 MEDIUM· v3 N/A· v2 An issue was discovered in WatchGuard EPDR 8.0.21.0002. It is possible to bypass the defensive capabilities by adding a registry key as SYSTEM. |
1Watchguard 4Edr Firmware Epdr FirmwareEpp Firmware+1 moreJun 17, 2026 Oct 5, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 An issue was discovered in WatchGuard EPDR 8.0.21.0002. Due to a weak implementation of message handling between WatchGuard EPDR processes, it is possible to perform a Local Privilege Escalation on Windows by sending a c...Show more |
A DLL hijacking vulnerability in Panda Security VPN for Windows prior to version v15.14.8 allows attackers to execute arbitrary code via placing a crafted DLL file in the same directory as PANDAVPN.exe. |
A stored cross-site scripting (XSS) vulnerability exists in the management web interface of WatchGuard Firebox and XTM appliances. A remote attacker can potentially execute arbitrary JavaScript code in the management web...Show more |
WatchGuard Firebox and XTM appliances allow a local attacker (that has already obtained shell access) to elevate their privileges and execute code with root permissions. This is fixed in Fireware OS 12.8.1, 12.5.10, and...Show more |
An integer overflow in WatchGuard Firebox and XTM appliances allows an unauthenticated remote attacker to trigger a buffer overflow and potentially execute arbitrary code by sending a malicious request to exposed managem...Show more |
WatchGuard Firebox and XTM appliances allow an unauthenticated remote attacker to retrieve sensitive authentication server settings by sending a malicious request to exposed authentication endpoints. This is fixed in Fir...Show more |