CVE-2024-6592

EUVD-2024-47657
An incorrect authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows and the WatchGuard Single Sign-On Client on Windows and MacOS allows an attacker with network access to forge communications to affected components.

In the event an attacker has already gained network access, they could exploit this vulnerability to retrieve authenticated usernames and group memberships from the Single Sign-On Agent or send arbitrary account and group information to the Single Sign-On Agent for their host. This vulnerability cannot be used by an attacker to gain access to user credentials.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
9.1 CRITICAL
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 64.89%
Affected Products (NVD)
VendorProductVersion
watchguardauthentication_gateway
𝑥
≤ 12.10.2
watchguardsingle_sign-on_client
𝑥
≤ 12.5.4
watchguardsingle_sign-on_client
𝑥
≤ 12.7
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
watchguardauthentication_gateway
𝑥
< 12.10.2
ADP
watchguardsingle_sign-on_client
𝑥
≤ 12.7
ADP
watchguardsingle_sign-on_client
𝑥
≤ 12.5.4
ADP