CVE-2015-3966: Innominate Mguard Firmware

Medium severity, CVSS 4.0. EPSS: 1.6% chance of exploitation in the next 30 days.

The IPsec SA establishment process on Innominate mGuard devices with firmware 8.x before 8.1.7 allows remote authenticated users to cause a denial of service (VPN service restart) by leveraging a peer relationship to send a crafted configuration with compression.

Affected products

  • Innominate Mguard Firmware: version 8.0.0 only; version 8.0.1 only; version 8.0.2 only; version 8.0.3 only; version 8.1.1 only; version 8.1.2 only; …

Published 2015-08-30. Last modified 2026-06-17.