{"api_version":"1","generated_at":"2026-07-23T03:37:57+00:00","cve":"CVE-2002-0528","urls":{"html":"https://cve.report/CVE-2002-0528","api":"https://cve.report/api/cve/CVE-2002-0528.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2002-0528","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2002-0528"},"summary":{"title":"CVE-2002-0528","description":"Watchguard SOHO firewall 5.0.35 unpredictably disables certain IP restrictions for customized services that were set before the administrator upgrades to 5.0.35, which could allow remote attackers to bypass the intended access control rules.","state":"PUBLISHED","assigner":"mitre","published_at":"2002-08-12 04:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"10","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0009.html","name":"http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0009.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://online.securityfocus.com/archive/1/266948","name":"http://online.securityfocus.com/archive/1/266948","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.iss.net/security_center/static/8814.php","name":"http://www.iss.net/security_center/static/8814.php","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"ISS X-Force Database: firebox-soho-bypass-restrictions (8814): WatchGuard Firebox SOHO allows users to bypass IP restrictions","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/4491","name":"http://www.securityfocus.com/bid/4491","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit","Patch","Vendor Advisory"],"title":"WatchGuard SOHO Firewall Vanishing IP Restrictions Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2002-0528","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2002-0528","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2002","cve_id":"528","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"h","cpe4":"watchguard","cpe5":"soho_firewall","cpe6":"5.0.35","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T02:49:28.786Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"watchguard-soho-bypass-restrictions(8814)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"http://www.iss.net/security_center/static/8814.php"},{"name":"4491","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/4491"},{"name":"20020410 [VulnWatch] KPMG-2002008: Watchguard SOHO IP Restrictions Flaw","tags":["mailing-list","x_refsource_VULNWATCH","x_transferred"],"url":"http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0009.html"},{"name":"20020410 KPMG-2002008: Watchguard SOHO IP Restrictions Flaw","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://online.securityfocus.com/archive/1/266948"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2002-04-10T00:00:00.000Z","descriptions":[{"lang":"en","value":"Watchguard SOHO firewall 5.0.35 unpredictably disables certain IP restrictions for customized services that were set before the administrator upgrades to 5.0.35, which could allow remote attackers to bypass the intended access control rules."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2002-06-15T09:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"watchguard-soho-bypass-restrictions(8814)","tags":["vdb-entry","x_refsource_XF"],"url":"http://www.iss.net/security_center/static/8814.php"},{"name":"4491","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/4491"},{"name":"20020410 [VulnWatch] KPMG-2002008: Watchguard SOHO IP Restrictions Flaw","tags":["mailing-list","x_refsource_VULNWATCH"],"url":"http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0009.html"},{"name":"20020410 KPMG-2002008: Watchguard SOHO IP Restrictions Flaw","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://online.securityfocus.com/archive/1/266948"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2002-0528","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Watchguard SOHO firewall 5.0.35 unpredictably disables certain IP restrictions for customized services that were set before the administrator upgrades to 5.0.35, which could allow remote attackers to bypass the intended access control rules."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"watchguard-soho-bypass-restrictions(8814)","refsource":"XF","url":"http://www.iss.net/security_center/static/8814.php"},{"name":"4491","refsource":"BID","url":"http://www.securityfocus.com/bid/4491"},{"name":"20020410 [VulnWatch] KPMG-2002008: Watchguard SOHO IP Restrictions Flaw","refsource":"VULNWATCH","url":"http://archives.neohapsis.com/archives/vulnwatch/2002-q2/0009.html"},{"name":"20020410 KPMG-2002008: Watchguard SOHO IP Restrictions Flaw","refsource":"BUGTRAQ","url":"http://online.securityfocus.com/archive/1/266948"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2002-0528","datePublished":"2002-06-11T04:00:00.000Z","dateReserved":"2002-06-07T00:00:00.000Z","dateUpdated":"2024-08-08T02:49:28.786Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2002-08-12 04:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":true,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:h:watchguard:soho_firewall:5.0.35:*:*:*:*:*:*:*","matchCriteriaId":"50480EED-CCD7-4494-BF47-C64DA5036857"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2002","CveId":"528","Ordinal":"1","Title":"CVE-2002-0528","CVE":"CVE-2002-0528","Year":"2002"},"notes":[{"CveYear":"2002","CveId":"528","Ordinal":"1","NoteData":"Watchguard SOHO firewall 5.0.35 unpredictably disables certain IP restrictions for customized services that were set before the administrator upgrades to 5.0.35, which could allow remote attackers to bypass the intended access control rules.","Type":"Description","Title":"CVE-2002-0528"},{"CveYear":"2002","CveId":"528","Ordinal":"2","NoteData":"2002-06-11","Type":"Other","Title":"Published"},{"CveYear":"2002","CveId":"528","Ordinal":"3","NoteData":"2002-06-15","Type":"Other","Title":"Modified"}]}}}