6.7

CVE-2023-26237

An issue was discovered in WatchGuard EPDR 8.0.21.0002. It is possible to bypass the defensive capabilities by adding a registry key as SYSTEM.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
WatchguardEpp Firmware Version < 8.00.22.0010
   WatchguardEpp Version-
WatchguardEdr Firmware Version < 8.00.22.0010
   WatchguardEdr Version-
WatchguardEpdr Firmware Version < 8.00.22.0010
   WatchguardEpdr Version-
WatchguardPanda Ad360 Firmware Version < 8.00.22.0010
   WatchguardPanda Ad360 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.01% 0.009
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
134c704f-9b21-4f2e-91b3-4a467353bcc0 6.7 0.8 5.9
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CWE-639 Authorization Bypass Through User-Controlled Key

The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.