Incorrect Authorization vulnerability in WatchGuard Authentication Gateway allows Authentication Bypass
CVE-2024-6592

9.3CRITICAL

Key Information:

Vendor

Watchguard

Vendor
CVE Published:
25 September 2024

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2024-6592?

An incorrect authorization vulnerability has been identified in the protocol communication between the WatchGuard Authentication Gateway (also known as the Single Sign-On Agent) and the WatchGuard Single Sign-On Client on both Windows and MacOS systems. This vulnerability allows for an authentication bypass, enabling unauthorized access to systems. Affected versions include the Authentication Gateway up to 12.10.2, the Windows Single Sign-On Client up to version 12.7, and the MacOS Single Sign-On Client up to 12.5.4. A patch is recommended for all users utilizing these specific versions to mitigate risks associated with this vulnerability.

Affected Version(s)

SSO Agent 12.0 <= 12.10.2

SSO Client macOS 12.0 <= 12.5.4

SSO Client Windows 12.0 <= 12.7

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

.