CVE-2018-10578: Input Validation
An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15, and AP300 devices with firmware before 2.0.0.10. Incorrect validation of the "old password" field in the change password form allows an attacker to bypass validation of this field.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2018-10578.
What is the severity level of CVE-2018-10578?
The severity level of CVE-2018-10578 is critical with a score of 9.8 out of 10.
Which WatchGuard devices and firmware versions are affected by CVE-2018-10578?
WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15, and AP300 devices with firmware before 2.0.0.10 are affected.
What is the impact of CVE-2018-10578?
The vulnerability allows an attacker to bypass validation of the "old password" field in the change password form.
Is there a fix available for CVE-2018-10578?
Yes, upgrading the firmware to version 1.2.9.15 for AP100, AP102, and AP200 devices, and version 2.0.0.10 for AP300 devices resolves the vulnerability.