← voltar
CVE-2024-6592criticalCWE-306

WatchGuard Firebox Single Sign-On Agent Protocol Authorization Bypass

48Vexday Risk Score

Sem sinal de exploração. Ela tem prova de conceito pública.

ssvc Attendcvss 9.3epss 1.2%
da publicação à arma0 dias
Publicada no NVD25 de set.
1ª PoC17 de set.
probabilidade de exploração
1.2%top 36% das CVEs
exploração observada
nãonenhuma fonte reporta
1 exploit(s) público(s)
An incorrect authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows and the WatchGuard Single Sign-On Client on Windows and MacOS allows an attacker with network access to forge communications to affected components. In the event an attacker has already gained network access, they could exploit this vulnerability to retrieve authenticated usernames and group memberships from the Single Sign-On Agent or send arbitrary account and group information to the Single Sign-On Agent for their host. This vulnerability cannot be used by an attacker to gain access to user credentials.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.