CVE-2023-37849: WatchGuard Panda Security VPN

Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.

A DLL hijacking vulnerability in Panda Security VPN for Windows prior to version v15.14.8 allows attackers to execute arbitrary code via placing a crafted DLL file in the same directory as PANDAVPN.exe.

Affected products

  • WatchGuard Panda Security VPN: before 15.14.8 (fixed in 15.14.8)

Published 2023-07-13. Last modified 2026-06-17.