Denial of Service Vulnerability in WatchGuard Single Sign-On Client for Windows
CVE-2024-6594

8.7HIGH

Key Information:

Vendor

Watchguard

Vendor
CVE Published:
25 September 2024

Badges

👾 Exploit Exists

What is CVE-2024-6594?

The WatchGuard Single Sign-On Client for Windows is vulnerable due to improper handling of exceptional conditions, allowing an attacker with network access to exploit this issue. By repeatedly sending malformed commands, the attacker can trigger a crash in the client, resulting in a denial of service condition for the Single Sign-On service. This vulnerability affects versions of the client up to 12.7, emphasizing the importance of patching and securing systems against unauthorized access.

Affected Version(s)

SSO Client Windows 12.0 <= 12.7

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • 👾

    Exploit known to exist

  • Vulnerability published

.