Vulnerabilities > Watchguard > Critical

DATE CVE VULNERABILITY TITLE RISK
2024-09-25 CVE-2024-6592 Incorrect Authorization vulnerability in Watchguard Authentication Gateway and Single Sign-On Client
Incorrect Authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows and the WatchGuard Single Sign-On Client on Windows and MacOS allows Authentication Bypass.This issue affects the Authentication Gateway: through 12.10.2; Windows Single Sign-On Client: through 12.7; MacOS Single Sign-On Client: through 12.5.4.
network
low complexity
watchguard CWE-863
critical
9.1
2024-09-25 CVE-2024-6593 Incorrect Authorization vulnerability in Watchguard Authentication Gateway
Incorrect Authorization vulnerability in WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows allows an attacker with network access to execute restricted management commands. This issue affects Authentication Gateway: through 12.10.2.
network
low complexity
watchguard CWE-863
critical
9.1
2022-09-06 CVE-2022-31789 Integer Overflow or Wraparound vulnerability in Watchguard Fireware
An integer overflow in WatchGuard Firebox and XTM appliances allows an unauthenticated remote attacker to trigger a buffer overflow and potentially execute arbitrary code by sending a malicious request to exposed management ports.
network
low complexity
watchguard CWE-190
critical
9.8
2022-06-07 CVE-2022-25361 Unspecified vulnerability in Watchguard Fireware
WatchGuard Firebox and XTM appliances allow an unauthenticated remote attacker to delete arbitrary files from a limited set of directories on the system.
network
low complexity
watchguard
critical
9.1
2022-03-04 CVE-2022-26318 Unspecified vulnerability in Watchguard Fireware
On WatchGuard Firebox and XTM appliances, an unauthenticated user can execute arbitrary code, aka FBX-22786.
network
low complexity
watchguard
critical
9.8
2018-05-02 CVE-2018-10578 Improper Input Validation vulnerability in Watchguard products
An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15, and AP300 devices with firmware before 2.0.0.10.
network
low complexity
watchguard CWE-20
critical
9.8
2018-04-30 CVE-2018-10575 Use of Hard-coded Credentials vulnerability in Watchguard Ap100 Firmware, Ap102 Firmware and Ap200 Firmware
An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15.
network
low complexity
watchguard CWE-798
critical
9.8