CVE-2024-6592
Severity CVSS v4.0:
Pending analysis
Type:
CWE-306
Missing Authentication for Critical Function
Publication date:
25/09/2024
Last modified:
15/10/2025
Description
Incorrect Authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows and the WatchGuard Single Sign-On Client on Windows and MacOS allows Authentication Bypass.This issue affects the Authentication Gateway: through 12.10.2; Windows Single Sign-On Client: through 12.7; MacOS Single Sign-On Client: through 12.5.4.
Impact
Base Score 3.x
9.10
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:watchguard:authentication_gateway:*:*:*:*:*:*:*:* | 12.10.2 (including) | |
| cpe:2.3:a:watchguard:single_sign-on_client:*:*:*:*:*:macos:*:* | 12.5.4 (including) | |
| cpe:2.3:a:watchguard:single_sign-on_client:*:*:*:*:*:windows:*:* | 12.7 (including) |
To consult the complete list of CPE names with products and versions, see this page



