Credential Disclosure Vulnerability in WatchGuard Fireware's AD Helper Component
CVE-2020-10532
7.5HIGH
Summary
A vulnerability in the AD Helper component of WatchGuard Fireware prior to version 5.8.5.10317 allows remote attackers to exploit the /domains/list URI to retrieve cleartext passwords. This exposure can lead to unauthorized access to sensitive information and potentially compromise system integrity. Organizations using affected versions of Fireware should prioritize updating to the latest version to mitigate the risks associated with this vulnerability.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved