Untangle maintains a focused line of network security appliances centered on its NG Firewall product, which performs traffic filtering and threat management for enterprise networks. The vulnerability profile centers on web-interface and input-handling weaknesses, including cross-site scripting, command injection, SQL injection, and inadequate encryption, consistent with the attack surface of internet-facing administrative and gateway software. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Untangle over time
Signals from CVEs in this vendor scope (7 CVEs).
7 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-33977HIGH untangle is a python library to convert XML data to python objects. untangle versions 1.2.0 and earlier improperly restricts recursive entity references in DTDs. By exploiting this | Jul 26, 2022 | 7.5 | 24 | NO | NO |
CVE-2022-31471HIGH untangle is a python library to convert XML data to python objects. untangle versions 1.2.0 and earlier improperly restricts XML external entity references. By exploiting this vuln | Jul 26, 2022 | 7.5 | 24 | NO | NO |
CVE-2019-18647HIGH The Untangle NG firewall 14.2.0 is vulnerable to an authenticated command injection when logged in as an admin user. | Nov 14, 2019 | 7.2 | 24 | NO | NO |
CVE-2019-18646HIGH The Untangle NG firewall 14.2.0 is vulnerable to authenticated inline-query SQL injection within the timeDataDynamicColumn parameter when logged in as an admin user. | Nov 14, 2019 | 7.2 | 23 | NO | NO |
CVE-2019-18649MEDIUM When logged in as an admin user, the Title input field (under Reports) within Untangle NG firewall 14.2.0 is vulnerable to stored XSS. | Nov 14, 2019 | 4.8 | 18 | NO | NO |
CVE-2019-18648MEDIUM When logged in as an admin user, the Untangle NG firewall 14.2.0 is vulnerable to reflected XSS at multiple places and specific user input fields. | Nov 14, 2019 | 4.8 | 18 | NO | NO |
CVE-2020-17494MEDIUM Untangle Firewall NG before 16.0 uses MD5 for passwords. | Nov 12, 2020 | 5.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (7 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Untangle.
Media articles that mention a CVE ID that affects a product developed by Untangle — matched by CVE ID, not by vendor name.