Show filters
77 Total Results
Displaying 11-20 of 77
Sort by:
Attacker Value
Unknown
CVE-2024-6592
Disclosure Date: September 25, 2024 (last updated October 02, 2024)
Incorrect Authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows and the WatchGuard Single Sign-On Client on Windows and MacOS allows Authentication Bypass.This issue affects the Authentication Gateway: through 12.10.2; Windows Single Sign-On Client: through 12.7; MacOS Single Sign-On Client: through 12.5.4.
0
Attacker Value
Unknown
CVE-2024-5974
Disclosure Date: July 09, 2024 (last updated January 13, 2025)
A buffer overflow in WatchGuard Fireware OS could may allow an authenticated remote attacker with privileged management access to execute arbitrary code with system privileges on the firewall.
This issue affects Fireware OS: from 11.9.6 through 12.10.3.
0
Attacker Value
Unknown
CVE-2024-4944
Disclosure Date: July 09, 2024 (last updated August 23, 2024)
A local privilege escalation vlnerability in the WatchGuard Mobile VPN with SSL client on Windows enables a local user to execute arbitrary commands with elevated privileged.
0
Attacker Value
Unknown
CVE-2024-1417
Disclosure Date: May 16, 2024 (last updated May 17, 2024)
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in WatchGuard AuthPoint Password Manager on MacOS allows an a adversary with local access to execute code under the context of the AuthPoint Password Manager application.
This issue affects AuthPoint Password Manager for MacOS versions before 1.0.6.
0
Attacker Value
Unknown
CVE-2024-3661
Disclosure Date: May 06, 2024 (last updated January 16, 2025)
DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that was expected to be protected by the VPN.
0
Attacker Value
Unknown
CVE-2023-26239
Disclosure Date: October 05, 2023 (last updated October 12, 2023)
An issue was discovered in WatchGuard EPDR 8.0.21.0002. Due to a weak implementation of a password check, it is possible to obtain credentials to access the management console as a non-privileged user.
0
Attacker Value
Unknown
CVE-2023-26238
Disclosure Date: October 05, 2023 (last updated October 12, 2023)
An issue was discovered in WatchGuard EPDR 8.0.21.0002. It is possible to enable or disable defensive capabilities by sending a crafted message to a named pipe.
0
Attacker Value
Unknown
CVE-2023-26237
Disclosure Date: October 05, 2023 (last updated October 12, 2023)
An issue was discovered in WatchGuard EPDR 8.0.21.0002. It is possible to bypass the defensive capabilities by adding a registry key as SYSTEM.
0
Attacker Value
Unknown
CVE-2023-26236
Disclosure Date: October 05, 2023 (last updated October 12, 2023)
An issue was discovered in WatchGuard EPDR 8.0.21.0002. Due to a weak implementation of message handling between WatchGuard EPDR processes, it is possible to perform a Local Privilege Escalation on Windows by sending a crafted message to a named pipe.
0
Attacker Value
Unknown
CVE-2023-37849
Disclosure Date: July 13, 2023 (last updated October 08, 2023)
A DLL hijacking vulnerability in Panda Security VPN for Windows prior to version v15.14.8 allows attackers to execute arbitrary code via placing a crafted DLL file in the same directory as PANDAVPN.exe.
0