First published: Thu Mar 12 2020(Updated: )
The AD Helper component in WatchGuard Fireware before 5.8.5.10317 allows remote attackers to discover cleartext passwords via the /domains/list URI.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Watchguard Ad Helper Firmware | <5.8.5.10317 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this issue is CVE-2020-10532.
The severity of CVE-2020-10532 is high with a CVSS score of 7.5.
The affected software of CVE-2020-10532 is WatchGuard Fireware before version 5.8.5.10317 with the AD Helper component.
Remote attackers can exploit CVE-2020-10532 by sending a request to the /domains/list URI to discover cleartext passwords.
Yes, you can find references for CVE-2020-10532 at the following links: 1. https://www.redteam-pentesting.de/en/advisories/rt-sa-2020-001/-credential-disclosure-in-watchguard-fireware-ad-helper-component 2. https://www.watchguard.com/help/docs/help-center/en-US/Content/en-US/Fireware/services/tdr/tdr_ad_helper_c.html