PT-2024-37744 · Watchguard · Watchguard Single Sign-On Client

Published

2024-09-25

·

Updated

2024-10-01

·

CVE-2024-6594

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions WatchGuard Single Sign-On Client versions through 12.7
Description The issue is related to improper handling of exceptional conditions in the WatchGuard Single Sign-On Client on Windows, causing the client to crash when handling malformed commands. An attacker with network access to the client could create a denial of service condition for the Single Sign-On service by repeatedly issuing malformed commands.
Recommendations For versions through 12.7, update to a version that fixes the improper handling of exceptional conditions to prevent the client from crashing due to malformed commands. As a temporary workaround, consider restricting network access to the Single Sign-On Client to minimize the risk of exploitation.

Fix

Improper Handling of Exceptional Conditions

Weakness Enumeration

Related Identifiers

CVE-2024-6594

Affected Products

Watchguard Single Sign-On Client