Securecomputing's vulnerability footprint centers on a modestly represented set of security and networking products, including the Sidewinder gateway, SecurityReporter, and embedded devices such as the SnapGear appliance and Samsung ADSL modems, reflecting a focus on perimeter defense and reporting infrastructure. The recurring weakness classes—including CSRF, improper authentication, path traversal, and NULL-pointer dereferences—recur across these products and reflect the authentication-handling and input-validation demands inherent to gateway and management-interface software. Vulnerabilities affecting this vendor tend toward moderate severity, while live exploitation activity, KEV catalog status, and current exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Securecomputing over time
Signals from CVEs in this vendor scope (20 CVEs).
20 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2007-4043CRITICAL file.cgi in Secure Computing SecurityReporter (aka Network Security Analyzer) before 4.6.3 allows remote attackers to bypass authentication via a name parameter ending with a "%00. | Jul 27, 2007 | 9.8 | 30 | NO | NO |
CVE-2004-0079HIGH The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake t | Nov 23, 2004 | 7.5 | 29 | NO | NO |
CVE-2020-36909HIGH SnapGear Management Console SG560 3.1.5 contains a file manipulation vulnerability that allows authenticated users to read, write, and delete files using the edit_config_files CGI | Jan 6, 2026 | 8.8 | 27 | NO | NO |
CVE-2020-36908HIGH SnapGear Management Console SG560 version 3.1.5 contains a cross-site request forgery vulnerability that allows attackers to perform administrative actions without user consent. At | Jan 6, 2026 | 8.8 | 27 | NO | NO |
CVE-2008-5540HIGH Secure Computing Secure Web Gateway (aka Webwasher), when Internet Explorer 6 or 7 is used, allows remote attackers to bypass detection of malware in an HTML document by placing an | Dec 12, 2008 | 9.3 | 23 | NO | NO |
CVE-2004-0112MEDIUM The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, whi | Nov 23, 2004 | 5.0 | 23 | NO | NO |
CVE-2006-4613HIGH Multiple unspecified vulnerabilities in SnapGear before 3.1.4u1 allow remote attackers to cause a denial of service via unspecified vectors involving (1) IPSec replay windows and ( | Sep 7, 2006 | 7.8 | 20 | NO | NO |
CVE-2008-1797HIGH Unspecified vulnerability in Secure Computing Webwasher 5.30 before build 3159 and 6.3.0 before build 3150 allows remote attackers to cause a denial of service (freeze) via a craft | Apr 15, 2008 | 7.1 | 19 | NO | NO |
CVE-2005-0865HIGH Samsung ADSL Modem SMDK8947v1.2 uses default passwords for the (1) root, (2) admin, or (3) user users, which allows remote attackers to gain privileges via Telnet or an HTTP reques | May 2, 2005 | 7.5 | 19 | NO | NO |
CVE-2004-2543MEDIUM Secure Computing Corporation Sidewinder G2 6.1.0.01 might allow remote attackers to cause a denial of service (proxy failure) via invalid traffic to the (1) T.120 or (2) RTSP proxy | Dec 31, 2004 | 5.0 | 19 | NO | NO |
Signals from CVEs in this vendor scope (20 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Securecomputing.
Media articles that mention a CVE ID that affects a product developed by Securecomputing — matched by CVE ID, not by vendor name.