Firewalls Family for Nessus

IDNameSeverity
179479Fortinet Fortigate SSH authentication bypass when RADIUS authentication is used (FG-IR-22-255)
critical
179407Zyxel USG < 5.37 / ATP < 5.37 / VPN < 5.37 Multiple Vulnerabilities
high
178464Zyxel USG < 5.37 Command Injection (CVE-2023-28767)
high
178148Fortinet Fortigate Proxy mode with deep inspection - Stack-based buffer overflow (FG-IR-23-183)
critical
178143Fortinet Fortigate Existing websocket connection persists after deleting API admin (FG-IR-23-028)
critical
177588Fortinet FortiNAC RCE (FG-IR-23-074)
critical
177387Fortinet Fortigate Authenticated user null pointer dereference in SSL-VPN (FG-IR-23-015)
medium
177264Fortinet Fortigate Lack of certificate verification when establishing secure connections (FG-IR-22-468)
medium
177127Fortinet Fortigate Out-of-bound write in CLI (FG-IR-22-494)
high
177126Fortinet Fortigate -resources CLI command (FG-IR-22-463)
high
177125Fortinet Fortigate Format String Bug in Fclicense daemon (FG-IR-23-119)
high
177124Fortinet Fortigate Access of uninitialized pointer in administrative interface API (FG-IR-23-095)
medium
177123Fortinet Fortigate - SMTP password ciphertext exposure in Log (FG-IR-22-455)
medium
177122Fortinet Fortigate Null pointer dereference in sslvnd (FG-IR-23-111)
high
177121Fortinet Fortigate Path traversal vulnerability in administrative interface (FG-IR-22-393)
low
177120Fortinet Fortigate Null pointer dereference in sslvpnd proxy endpoint (FG-IR-23-125)
medium
177119Fortinet Fortigate DoS in firmware upgrade function (FG-IR-22-375)
medium
177118Fortinet FortiWeb DoS in firmware upgrade function (FG-IR-22-375)
medium
177117Fortinet Fortigate Read Only administrator can intercept sensitive data (FG-IR-22-380)
medium
177116Fortinet Fortigate Heap buffer overflow in sslvpn pre-authentication (FG-IR-23-097)
critical
176894Zyxel NAS < 5.21 / USG < 4.35 / ATP < 4.35 / VPN < 4.35 / ZyWALL < 4.35 RCE (CVE-2020-9054)
critical
176416Zyxel USG < 4.35 / ATP < 4.35 / VPN < 4.35 / ZyWALL < 4.35 (RCE) (CVE-2020-9054)
critical
176238Zyxel Command Injection (CVE-2023-28771) (Direct Check)
critical
176216Zyxel USG < 5.36 / ATP < 5.36 / VPN < 5.36 / ZyWALL < 4.73 Patch 1 (RCE) (CVE-2023-28771)
critical
175084Fortinet Fortigate Out-of-bound-write in sslvpnd (FG-IR-22-475)
high
174404Fortinet Fortigate Ability to modify privileges from Custom to Read-Write (FG-IR-22-346)
medium
174403Fortinet Fortigate Lack of certificate verification when establishing secure connections with threat feed fabric connectors (FG-IR-22-257)
high
174402Fortinet Fortigate Header injection in proxy login page (FG-IR-22-362)
medium
174401Fortinet Fortigate Flaws over DHCP and DNS keys encryption scheme (FG-IR-22-080)
low
174265Fortinet FortiWeb OS command injection in CLI (FG-IR-22-186)
high
174264Fortinet Fortigate xss (FG-IR-22-363)
medium
174263Fortinet Fortigate Policy-based NGFW SSL VPN mode doesn't filter accesses via Bookmarks (FG-IR-22-381)
medium
174262Fortinet Fortigate (FG-IR-22-444)
high
174258Fortinet FortiWeb xss (FG-IR-22-428)
medium
174237Fortinet Fortigate Open redirect in sslvpnd (FG-IR-22-479)
medium
174223Fortinet Fortigate xss (FG-IR-22-224)
medium
173302SonicWall SonicOS Buffer Overflow (SNWLID-2023-0004)
high
172582Zyxel USG Hardcoded Default Password (CVE-2020-29583)
critical
172579Fortinet FortiOS - Path Traversal Vulnerability (FG-IR-22-401)
high
172492Fortinet FortiOS - Information Disclosure (FG-IR-22-364)
medium
172491Fortinet FortiOS - Path Traversal in Execute Command (FG-IR-22-369)
high
172440SonicWall SonicOS Security Misconfiguration (SNWLID-2023-0005)
high
172395Fortinet Fortigate Access of NULL pointer in SSLVPNd (FG-IR-22-477)
medium
172390Fortinet Fortigate Heap buffer underflow in administrative interface (FG-IR-23-001)
critical
172258Zyxel Unified Security Gateway (USG) Local Detection
info
172171Fortinet FortiWeb Stack-based buffer overflows in Proxyd (FG-IR-21-186)
critical
171902Fortinet FortiWeb Stack based buffer overflow in SAML management (FG-IR-22-151)
high
171888Fortinet Fortigate Padding oracle in cookie encryption (FG-IR-21-126)
medium
171887Fortinet FortiWeb Padding oracle in cookie encryption (FG-IR-21-126)
medium
171852Fortinet Fortigate Arbitrary read/write vulnerability in administrative interface (FG-IR-22-391)
high