Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-26239: WatchGuard EPDR and AD360 Local Protection Management Password Exposure Vulnerability | WatchGuard Technologies

An issue was discovered in WatchGuard EPDR 8.0.21.0002. Due to a weak implementation of a password check, it is possible to obtain credentials to access the management console as a non-privileged user.

CVE
#vulnerability

Advisory ID

WGSA-2023-00007

Published Date

2023-09-28

Workaround Available

False

CVSS Vector

AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Summary

WatchGuard EPDR and Panda AD360 versions up to, and including, 8.00.22.0009 allows an adversary with local access to recover the local protection management password by monitoring inter-process communications.

Affected

WatchGuard EPDR and Panda AD360 versions before 8.00.22.0010

Resolution

WatchGuard EPDR and Panda AD360 version 8.00.22.0010

Credits

Marcos Díaz Castiñeiras (https://www.linkedin.com/in/mdiazcast/) and Antón Ortigueira Vázquez (https://www.linkedin.com/in/antonortigueira/) from BlackArrow (Tarlogic).

Advisory Product List

Product Family

Product Branch

Product List

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda
CVE-2023-6905
CVE-2023-6903
CVE-2023-6904
CVE-2023-3907