WatchGuard Firebox Single Sign-On Agent Protocol Authorization Bypass
48Vexday Risk Score
Sin señal de explotación. Ella tiene prueba de concepto pública.
ssvc Attendcvss 9.3epss 1.2%
de la publicación al arma0 días
Publicada en NVD25 sept
1ª PoC17 sept
probabilidad de explotación
1.2%top 36% de las CVE
explotación observada
noninguna fuente lo reporta
1 exploit(s) público(s)
An incorrect authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows and the WatchGuard Single Sign-On Client on Windows and MacOS allows an attacker with network access to forge communications to affected components.
In the event an attacker has already gained network access, they could exploit this vulnerability to retrieve authenticated usernames and group memberships from the Single Sign-On Agent or send arbitrary account and group information to the Single Sign-On Agent for their host. This vulnerability cannot be used by an attacker to gain access to user credentials.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
PoCs públicas encontradas — 1
githubgithub.com/RedTeamPentesting/watchguard-sso-client★ 3⚠ Recursos públicos, para evaluar la exposición de sistemas que controlas o estás autorizado a probar. Prueba solo con autorización.