216.73.217.22

CVE-2024-6592

· Published 25/09/2024 12:15 · Modified 01/10/2024 16:06

Labels: CVE-2024-6592 2024-09-255d1c2695-1a31-4499-88ae-e847036fd7e3CVE-2024-6592CWE-863

Essential information

Published
25/09/2024 12:15
Modified
01/10/2024 16:06
Author
Creator
CVSS
9.1 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CVSS metrics

Description

Incorrect Authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows and the WatchGuard Single Sign-On Client on Windows and MacOS allows Authentication Bypass.This issue affects the Authentication Gateway: through 12.10.2; Windows Single Sign-On Client: through 12.7; MacOS Single Sign-On Client: through 12.5.4.

NVD status

Status
Analyzed — CVE has been recently published to the CVE List and has been received by the NVD.
Source
5d1c2695-1a31-4499-88ae-e847036fd7e3
NVD
View on NVD

Affected products (CPE)

ProductCPE
watchguard / authentication gateway cpe:2.3:a:watchguard:authentication_gateway:*:*:*:*:*:*:*:*
watchguard / single sign-on client cpe:2.3:a:watchguard:single_sign-on_client:*:*:*:*:*:macos:*:*
watchguard / single sign-on client cpe:2.3:a:watchguard:single_sign-on_client:*:*:*:*:*:windows:*:*

References