VendorsUntangleng_firewall14.2.0
Vulnerabilities

Untangle NG Firewall 14.2.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

4CVEs
CVE-2019-18647
The Untangle NG firewall 14.2.0 is vulnerable to an authenticated command injection when logged in as an admin user.
Published 2019-11-14 · Modified
9.0EPSS 0.019
CVE-2019-18646
The Untangle NG firewall 14.2.0 is vulnerable to authenticated inline-query SQL injection within the timeDataDynamicColumn parameter when logged in as an admin user.
Published 2019-11-14 · Modified
7.2EPSS 0.009
CVE-2019-18648
When logged in as an admin user, the Untangle NG firewall 14.2.0 is vulnerable to reflected XSS at multiple places and specific user input fields.
Published 2019-11-14 · Modified
4.8EPSS 0.005
CVE-2019-18649
When logged in as an admin user, the Title input field (under Reports) within Untangle NG firewall 14.2.0 is vulnerable to stored XSS.
Published 2019-11-14 · Modified
4.8EPSS 0.005