CVE-2023-4400: Medium severity skyhigh security secure web gateway vulnerability

Published Sep 13, 2023
·
Updated

A password management vulnerability in Skyhigh Secure Web Gateway (SWG) in main releases 11.x prior to 11.2.14, 10.x prior to 10.2.25 and controlled release 12.x prior to 12.2.1, allows some authentication information stored in configuration files to be extracted through SWG REST API. This was possible due to SWG storing the password in plain text in some configuration files.

Affected Software

3 affected components
Skyhighsecurity Secure Web Gateway>=10.0.0<10.2.25
Skyhighsecurity Secure Web Gateway>=11.0.0<11.2.14
Skyhighsecurity Secure Web Gateway>=12.0.0<12.2.1

Event History

Sep 13, 2023
CVE Published
via MITRE·06:53 AM
Data Sourced
via MITRE·06:53 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·07:15 AM
DescriptionSeverityWeaknessAffected Software

Frequently Asked Questions

1

What is the vulnerability ID for this password management vulnerability?

The vulnerability ID for this password management vulnerability is CVE-2023-4400.

2

What is the severity of CVE-2023-4400?

The severity of CVE-2023-4400 is medium with a severity value of 6.2.

3

Which versions of Skyhigh Secure Web Gateway are affected by this vulnerability?

Versions 10.x prior to 10.2.25, 11.x prior to 11.2.14, and controlled release 12.x prior to 12.2.1 of Skyhigh Secure Web Gateway are affected by this vulnerability.

4

How can the authentication information be extracted through SWG REST API?

The authentication information can be extracted through SWG REST API by accessing the configuration files.

5

How can I fix this password management vulnerability?

To fix this vulnerability, update to main releases 11.x version 11.2.14, 10.x version 10.2.25, or controlled release 12.x version 12.2.1 of Skyhigh Secure Web Gateway.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203