CVE-2018-10576

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
30/04/2018
Last modified:
16/09/2018

Description

An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15. Improper authentication handling by the native Access Point web UI allows authentication using a local system account (instead of the dedicated web-only user).

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:watchguard:ap200_firmware:*:*:*:*:*:*:*:* 1.2.9.15 (excluding)
cpe:2.3:h:watchguard:ap200:-:*:*:*:*:*:*:*
cpe:2.3:o:watchguard:ap102_firmware:*:*:*:*:*:*:*:* 1.2.9.15 (excluding)
cpe:2.3:h:watchguard:ap102:-:*:*:*:*:*:*:*
cpe:2.3:o:watchguard:ap100_firmware:*:*:*:*:*:*:*:* 1.2.9.15 (excluding)
cpe:2.3:h:watchguard:ap100:-:*:*:*:*:*:*:*