Vulnerabilities > CVE-2024-6592 - Incorrect Authorization vulnerability in Watchguard Authentication Gateway and Single Sign-On Client

047910
CVSS 9.1 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
NONE
network
low complexity
watchguard
CWE-863
critical

Summary

Incorrect Authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows and the WatchGuard Single Sign-On Client on Windows and MacOS allows Authentication Bypass.This issue affects the Authentication Gateway: through 12.10.2; Windows Single Sign-On Client: through 12.7; MacOS Single Sign-On Client: through 12.5.4.

Vulnerable Configurations

Part Description Count
Application
Watchguard
3

Common Weakness Enumeration (CWE)