CVE-2024-6592

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
25/09/2024
Last modified:
15/10/2025

Description

Incorrect Authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows and the WatchGuard Single Sign-On Client on Windows and MacOS allows Authentication Bypass.This issue affects the Authentication Gateway: through 12.10.2; Windows Single Sign-On Client: through 12.7; MacOS Single Sign-On Client: through 12.5.4.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:watchguard:authentication_gateway:*:*:*:*:*:*:*:* 12.10.2 (including)
cpe:2.3:a:watchguard:single_sign-on_client:*:*:*:*:*:macos:*:* 12.5.4 (including)
cpe:2.3:a:watchguard:single_sign-on_client:*:*:*:*:*:windows:*:* 12.7 (including)


References to Advisories, Solutions, and Tools