HIGH · 7.8

CVE-2018-10576

An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15. Improper authentication handling by the native Access Point web UI allows authentication using a lo...

Vulnerability Description

An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15. Improper authentication handling by the native Access Point web UI allows authentication using a local system account (instead of the dedicated web-only user).

CVSS Score

7.8

HIGH

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
HIGH

Affected Products

VendorProductVersions
WatchguardAp200 Firmware< 1.2.9.15
WatchguardAp200-
WatchguardAp102 Firmware< 1.2.9.15
WatchguardAp102-
WatchguardAp100 Firmware< 1.2.9.15
WatchguardAp100-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2018-10576?

CVE-2018-10576 is a vulnerability with a CVSS score of 7.8 (HIGH). An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15. Improper authentication handling by the native Access Point web UI allows authentication using a lo...

How severe is CVE-2018-10576?

CVE-2018-10576 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2018-10576?

Check the references section above for vendor advisories and patch information. Affected products include: Watchguard Ap200 Firmware, Watchguard Ap200, Watchguard Ap102 Firmware, Watchguard Ap102, Watchguard Ap100 Firmware.