Support Us — Your donation helps us keep running

Goal: 1000 CNY,Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2024-6592
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
WatchGuard Firebox Single Sign-On Agent Protocol Authorization Bypass
Source: NVD (National Vulnerability Database)
Vulnerability Description
Incorrect Authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows and the WatchGuard Single Sign-On Client on Windows and MacOS allows Authentication Bypass.This issue affects the Authentication Gateway: through 12.10.2; Windows Single Sign-On Client: through 12.7; MacOS Single Sign-On Client: through 12.5.4.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Source: NVD (National Vulnerability Database)
Vulnerability Type
关键功能的认证机制缺失
Source: NVD (National Vulnerability Database)
Vulnerability Title
WatchGuard Authentication Gateway 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
WatchGuard Authentication Gateway(WatchGuard Single Sign-On Agent)是美国WatchGuard公司的一个身份验证网关。 WatchGuard Authentication Gateway 12.10.2及之前版本存在安全漏洞,该漏洞源于在Windows和macOS上的协议通信中存在授权错误,允许攻击者进行认证绕过。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
WatchGuardAuthentication Gateway 0 ~ 12.10.2 -
WatchGuardSingle Sign-On Client 0 ~ 12.7 -
WatchGuardSingle Sign-On Client 0 ~ 12.5.4 -
II. Public POCs for CVE-2024-6592
#POC DescriptionSource LinkShenlong Link
1Client Implementation for the WatchGuard SSO Agent Protocol used for Security Research (CVE-2024-6592, CVE-2024-6593, CVE-2024-6594)https://github.com/RedTeamPentesting/watchguard-sso-clientPOC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2024-6592
Please Login to view more intelligence information
New Vulnerabilities
V. Comments for CVE-2024-6592

No comments yet


Leave a comment