9.3
CVE-2026-57910
- EPSS 0.2%
- Veröffentlicht 25.08.2026 11:47:49
- Zuletzt bearbeitet 28.09.2026 23:10:00
- Erkennungen
WatchGuard Agent improper authentication allows unauthenticated remote code execution
Improper authentication in the WatchGuard Agent allows an unauthenticated attacker with network access to cause the agent to execute arbitrary code with elevated privileges.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerWatchGuard
≫
Produkt
WatchGuard Agent
Default Statusunaffected
Version
0
Version <
1.17.01.0000
Status
affected
HerstellerWatchGuard
≫
Produkt
WatchGuard Agent
Default Statusunaffected
Version
0
Version <
1.25.13.0000
Status
affected
HerstellerWatchGuard
≫
Produkt
WatchGuard Agent
Default Statusunaffected
Version
0
Version <
1.17.21.0000
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.2% | 0.094 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 5d1c2695-1a31-4499-88ae-e847036fd7e3 | 9.3 | 0 | 0 |
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
CWE-306 Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
CWE-347 Improper Verification of Cryptographic Signature
The product does not verify, or incorrectly verifies, the cryptographic signature for data.
CWE-494 Download of Code Without Integrity Check
The product downloads source code or an executable from a remote location and executes the code without sufficiently verifying the origin and integrity of the code.
Für Zugriff zu Vulnerability Intelligence ist ein VulnDex Zugang erforderlich.
https://psirt.watchguard.com/CVE-2026-57910