PT-2024-6526 · Watchguard · Watchguard Authentication Gateway+2

CVE-2024-6592

·

Published

2024-09-25

·

Updated

2026-08-08

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions: WatchGuard Authentication Gateway versions through 12.10.2 Windows Single Sign-On Client versions through 12.7 MacOS Single Sign-On Client versions through 12.5.4
Description: The issue is related to an Incorrect Authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway and the WatchGuard Single Sign-On Client. This vulnerability allows Authentication Bypass. The vulnerability can be exploited by a remote attacker to gain unauthorized access.
Recommendations: For WatchGuard Authentication Gateway versions through 12.10.2, update to a newer version to secure systems from attack. For Windows Single Sign-On Client versions through 12.7, update to a newer version to secure systems from attack. For MacOS Single Sign-On Client versions through 12.5.4, update to a newer version to secure systems from attack. As a temporary workaround, consider enabling Multi-Factor Authentication (MFA) and monitor for signs of compromise.

Fix

Missing Authentication

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-07668
CVE-2024-6592

Affected Products

Macos Single Sign-On Client
Watchguard Authentication Gateway
Windows Single Sign-On Client