Vulnerabilities > Watchguard

DATE CVE VULNERABILITY TITLE RISK
2017-04-22 CVE-2017-8055 Information Exposure Through Discrepancy vulnerability in Watchguard Fireware 11.0.2/11.1/11.2.1
WatchGuard Fireware allows user enumeration, e.g., in the Firebox XML-RPC login handler.
network
low complexity
watchguard CWE-203
5.3
2016-08-24 CVE-2016-7089 Permissions, Privileges, and Access Controls vulnerability in Watchguard Rapidstream
WatchGuard RapidStream appliances allow local users to gain privileges and execute arbitrary commands via a crafted ifconfig command, aka ESCALATEPLOWMAN.
local
low complexity
watchguard CWE-264
7.8
2016-04-18 CVE-2016-3943 Incorrect Default Permissions vulnerability in Watchguard Panda Endpoint Administration Agent 7.49
Panda Endpoint Administration Agent before 7.50.00, as used in Panda Security for Business products for Windows, uses a weak ACL for the Panda Security/WaAgent directory and sub-directories, which allows local users to gain SYSTEM privileges by modifying an executable module.
local
low complexity
watchguard CWE-276
7.8
2016-04-18 CVE-2015-7378 Incorrect Default Permissions vulnerability in Watchguard Panda URL Filtering 4.3.1.8
Panda Security URL Filtering before 4.3.1.9 uses a weak ACL for the "Panda Security URL Filtering" directory and installed files, which allows local users to gain SYSTEM privileges by modifying Panda_URL_Filteringb.exe.
local
low complexity
watchguard CWE-276
7.8