untangle records
5 published records for vendor untangle.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-326 Inadequate Encryption Strength1
- CWE-77 Improper Neutralization of Special Elements used in a Command ('Command Injection')1
- CWE-89 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')1
The weakness classes this vendor ships most often: where to look.
CWEAll records
5 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
29Monitor | CVE-2019-18647No exploit | The Untangle NG firewall 14.2.0 is vulnerable to an authenticated command injection when logged in as an admin user.untangle · ng firewall · CWE-77 | High7.2 | — | 1.9% | Nov 14, 2019 |
28Monitor | CVE-2019-18646No exploit | The Untangle NG firewall 14.2.0 is vulnerable to authenticated inline-query SQL injection within the timeDataDynamicColumn parameter when lountangle · ng firewall · CWE-89 | High7.2 | — | 0.9% | Nov 14, 2019 |
21Monitor | CVE-2020-17494No exploit | Untangle Firewall NG before 16.0 uses MD5 for passwords.untangle · untangle firewall ng · CWE-326 | Medium5.3 | — | 0.8% | Nov 12, 2020 |
19Monitor | CVE-2019-18648No exploit | When logged in as an admin user, the Untangle NG firewall 14.2.0 is vulnerable to reflected XSS at multiple places and specific user input funtangle · ng firewall · CWE-79 | Medium4.8 | — | 0.5% | Nov 14, 2019 |
19Monitor | CVE-2019-18649No exploit | When logged in as an admin user, the Title input field (under Reports) within Untangle NG firewall 14.2.0 is vulnerable to stored XSS.untangle · ng firewall · CWE-79 | Medium4.8 | — | 0.5% | Nov 14, 2019 |
- CVE-2019-1864729Monitor
The Untangle NG firewall 14.2.0 is vulnerable to an authenticated command injection when logged in as an admin user.
HighCVSS 7.2No exploitEPSS 2%untangle · ng firewallNov 14, 2019
- CVE-2019-1864628Monitor
The Untangle NG firewall 14.2.0 is vulnerable to authenticated inline-query SQL injection within the timeDataDynamicColumn parameter when lo
HighCVSS 7.2No exploitEPSS 1%untangle · ng firewallNov 14, 2019
- CVE-2020-1749421Monitor
Untangle Firewall NG before 16.0 uses MD5 for passwords.
MediumCVSS 5.3No exploitEPSS 1%untangle · untangle firewall ngNov 12, 2020
- CVE-2019-1864819Monitor
When logged in as an admin user, the Untangle NG firewall 14.2.0 is vulnerable to reflected XSS at multiple places and specific user input f
MediumCVSS 4.8No exploitEPSS 1%untangle · ng firewallNov 14, 2019
- CVE-2019-1864919Monitor
When logged in as an admin user, the Title input field (under Reports) within Untangle NG firewall 14.2.0 is vulnerable to stored XSS.
MediumCVSS 4.8No exploitEPSS 1%untangle · ng firewallNov 14, 2019