CVE-2024-6593: WatchGuard Firebox Single Sign-On Agent Management Interface Authentication Bypass
Incorrect Authorization vulnerability in WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows allows an attacker with network access to execute restricted management commands.
An attacker that has already gained network access could exploit this vulnerability to retrieve authenticated usernames and group memberships from the Single Sign-On Agent or tamper with the agent configuration. This vulnerability cannot be used by an attacker to gain access to user credentials.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6593?
CVE-2024-6593 is considered a high severity vulnerability due to incorrect authorization that allows execution of restricted management commands.
How do I fix CVE-2024-6593?
To fix CVE-2024-6593, update the WatchGuard Authentication Gateway to version 12.10.3 or later.
Who is affected by CVE-2024-6593?
CVE-2024-6593 affects users of WatchGuard Authentication Gateway versions up to and including 12.10.2.
What type of vulnerability is CVE-2024-6593?
CVE-2024-6593 is an Incorrect Authorization vulnerability in the WatchGuard Authentication Gateway.
What can an attacker achieve with CVE-2024-6593?
An attacker with network access can execute restricted management commands due to the Incorrect Authorization in CVE-2024-6593.