PT-2024-6526 · Watchguard · Windows Single Sign-On Client+2

Published

2024-09-25

·

Updated

2025-10-15

·

CVE-2024-6592

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions: WatchGuard Authentication Gateway versions through 12.10.2 Windows Single Sign-On Client versions through 12.7 MacOS Single Sign-On Client versions through 12.5.4
Description: The issue is related to an Incorrect Authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway and the WatchGuard Single Sign-On Client. This vulnerability allows Authentication Bypass. The vulnerability can be exploited by a remote attacker to gain unauthorized access.
Recommendations: For WatchGuard Authentication Gateway versions through 12.10.2, update to a newer version to secure systems from attack. For Windows Single Sign-On Client versions through 12.7, update to a newer version to secure systems from attack. For MacOS Single Sign-On Client versions through 12.5.4, update to a newer version to secure systems from attack. As a temporary workaround, consider enabling Multi-Factor Authentication (MFA) and monitor for signs of compromise.

Fix

Incorrect Authorization

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-07668
CVE-2024-6592

Affected Products

Macos Single Sign-On Client
Watchguard Authentication Gateway
Windows Single Sign-On Client