RSS   Vulnerabilities for 'Mguard firmware'   RSS

2015-08-30
 
CVE-2015-3966

 

 
The IPsec SA establishment process on Innominate mGuard devices with firmware 8.x before 8.1.7 allows remote authenticated users to cause a denial of service (VPN service restart) by leveraging a peer relationship to send a crafted configuration with compression.

 
2014-12-19
 
CVE-2014-9193

CWE-264
 

 
Innominate mGuard with firmware before 7.6.6 and 8.x before 8.1.4 allows remote authenticated admins to obtain root privileges by changing a PPP configuration setting.

 
2014-07-30
 
CVE-2014-2356

CWE-200
 

 
Innominate mGuard before 7.6.4 and 8.x before 8.0.3 does not require authentication for snapshot downloads, which allows remote attackers to obtain sensitive information via a crafted HTTPS request.

 
2012-06-19
 
CVE-2012-3006

CWE-310
 

 
The Innominate mGuard Smart HW before HW-101130 and BD before BD-101030, mGuard industrial RS, mGuard delta HW before HW-103060 and BD before BD-211010, mGuard PCI, mGuard blade, and EAGLE mGuard appliances with software before 7.5.0 do not use a sufficient source of entropy for private keys, which makes it easier for man-in-the-middle attackers to spoof (1) HTTPS or (2) SSH servers by predicting a key value.

 

 >>> Vendor: Innominate 7 Products
Eagle mguard
Mguard blade
Mguard delta
Mguard industrial rs
Mguard pci
Mguard smart
Mguard firmware


Copyright 2024, cxsecurity.com

 

Back to Top