9.3

CVE-2024-6592

WatchGuard Firebox Single Sign-On Agent Protocol Authorization Bypass

An incorrect authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows and the WatchGuard Single Sign-On Client on Windows and MacOS allows an attacker with network access to forge communications to affected components.

In the event an attacker has already gained network access, they could exploit this vulnerability to retrieve authenticated usernames and group memberships from the Single Sign-On Agent or send arbitrary account and group information to the Single Sign-On Agent for their host. This vulnerability cannot be used by an attacker to gain access to user credentials.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
WatchguardAuthentication Gateway Version <= 12.10.2
WatchguardSingle Sign-on Client SwPlatformmacos Version <= 12.5.4
WatchguardSingle Sign-on Client SwPlatformwindows Version <= 12.7
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.16% 0.641
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.1 3.9 5.2
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
5d1c2695-1a31-4499-88ae-e847036fd7e3 9.3 0 0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CWE-306 Missing Authentication for Critical Function

The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

CWE-863 Incorrect Authorization

The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.

https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2024-00014
Vendor Advisory
Mitigation
https://psirt.watchguard.com/CVE-2024-6592
https://www.redteam-pentesting.de/advisories/rt-sa-2024-006