CVE-2023-4400: Medium severity skyhigh security secure web gateway vulnerability
A password management vulnerability in Skyhigh Secure Web Gateway (SWG) in main releases 11.x prior to 11.2.14, 10.x prior to 10.2.25 and controlled release 12.x prior to 12.2.1, allows some authentication information stored in configuration files to be extracted through SWG REST API. This was possible due to SWG storing the password in plain text in some configuration files.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this password management vulnerability?
The vulnerability ID for this password management vulnerability is CVE-2023-4400.
What is the severity of CVE-2023-4400?
The severity of CVE-2023-4400 is medium with a severity value of 6.2.
Which versions of Skyhigh Secure Web Gateway are affected by this vulnerability?
Versions 10.x prior to 10.2.25, 11.x prior to 11.2.14, and controlled release 12.x prior to 12.2.1 of Skyhigh Secure Web Gateway are affected by this vulnerability.
How can the authentication information be extracted through SWG REST API?
The authentication information can be extracted through SWG REST API by accessing the configuration files.
How can I fix this password management vulnerability?
To fix this vulnerability, update to main releases 11.x version 11.2.14, 10.x version 10.2.25, or controlled release 12.x version 12.2.1 of Skyhigh Secure Web Gateway.