Vulnerabilities > Sofaware

DATE CVE VULNERABILITY TITLE RISK
2007-06-27 CVE-2007-3465 Remote Security vulnerability in Safe At Office 500 Utm
Check Point SofaWare Safe@Office, with firmware before Embedded NGX 7.0.45 GA, has a certain default password.
network
low complexity
sofaware
critical
10.0
2007-06-27 CVE-2007-3464 Denial-Of-Service vulnerability in Safe At Office 500 Utm
Check Point SofaWare Safe@Office, with firmware before Embedded NGX 7.0.45 GA, does not require entry of the old password when changing the admin password, which might allow attackers to gain privileges by conducting a CSRF attack, making a password change on an unattended workstation, or other vectors.
network
sofaware
8.5
2007-06-27 CVE-2007-3462 Cross-Site Request Forgery vulnerability in Sofaware Safe AT Office 500 UTM Embeddedngx7.0.39Ga
Cross-site request forgery (CSRF) vulnerability in Check Point SofaWare Safe@Office, with firmware before Embedded NGX 7.0.45 GA, allows remote attackers to execute commands as arbitrary users, and disable firewalling of the protected network.
network
sofaware
6.0