Shorewall is a modestly represented firewall and network packet filtering tool deployed on Linux systems to manage iptables-based rule enforcement and stateful traffic control. The observed disclosures center on the core firewall configuration and filtering product itself, with weakness classifications reflecting generic misconfiguration or logic-related concerns typical of policy-driven network security tools. Current severity, exploitation activity, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Shorewall over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2005-2317HIGH Shorewall 2.4.x before 2.4.1, 2.2.x before 2.2.5, and 2.0.x before 2.0.17, when MACLIST_TTL is greater than 0 or MACLIST_DISPOSITION is set to ACCEPT, allows remote attackers with | Jul 19, 2005 | 7.5 | 20 | NO | NO |
CVE-2004-0647MEDIUM shorewall 1.4.10c and earlier, and 2.0.x before 2.0.3a, allows local users to overwrite arbitrary files via a symlink attack on the chains-$$ temporary file. | Aug 6, 2004 | 4.6 | 14 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Shorewall.
Media articles that mention a CVE ID that affects a product developed by Shorewall — matched by CVE ID, not by vendor name.