VulnerabilityModified
CVE-2018-10576
Improper authentication handling by the native Access Point web UI allows authentication using a local system account (instead of the dedicated web-only user).
HIGH 7.8EPSS 1.50%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.50%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15. Improper authentication handling by the native Access Point web UI allows authentication using a local system account (instead of the dedicated web-only user).
- CVSS 3.0
- 7.8 HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.50% probability · 73th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-287
- Affected
- watchguard/ap200 firmware · watchguard/ap102 firmware · watchguard/ap100 firmware
- Source
- cve@mitre.org
References
- http://seclists.org/fulldisclosure/2018/May/12Mailing List, Third Party Advisory
- https://watchguardsupport.secure.force.com/publicKB?type=KBSecurityIssues&SFDCID=kA62A0000000LIyVendor Advisory
- https://www.exploit-db.com/exploits/45409/
- https://www.watchguard.com/wgrd-blog/new-firmware-available-ap100ap102ap200ap300-security-vulnerability-fixesVendor Advisory
- http://seclists.org/fulldisclosure/2018/May/12Mailing List, Third Party Advisory
- https://watchguardsupport.secure.force.com/publicKB?type=KBSecurityIssues&SFDCID=kA62A0000000LIyVendor Advisory
- https://www.exploit-db.com/exploits/45409/
- https://www.watchguard.com/wgrd-blog/new-firmware-available-ap100ap102ap200ap300-security-vulnerability-fixesVendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.