CVE Feed

    Dashboard / CVE / CVE-2024-6592

    CVE-2024-6592

    An incorrect authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows and the WatchGuard Single Sign-On Client on Windows and MacOS allows an attacker with network access to forge communications to affected components. In the event an attacker has already gained network access, they could exploit this vulnerability to retrieve authenticated usernames and group memberships from the Single Sign-On Agent or send arbitrary account and group information to the Single Sign-On Agent for their host. This vulnerability cannot be used by an attacker to gain access to user credentials.

    Published:Sep 25, 2024
    Last Modified:Aug 7, 2026
    EPS:Sep 25, 2024
    EPSS Score:0.01026
    CVSS Score:9.1

    Affected Products

    Vendor
    Watchguard
    Product
    Authentication Gateway
    Vendor
    Watchguard
    Product
    Single Sign-on Client
    Vendor
    Watchguard
    Product
    Sso Agent
    Vendor
    Watchguard
    Product
    Sso Client

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High