An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15. Improper authentication handling by the native Access Point web UI allows authentication using a local system account (instead of the dedicated web-only user).
2018-04-30T22:29:00.373
2024-11-21T03:41:35.670
Modified
CVSSv3.0: 7.8 (HIGH)
AV:L/AC:L/Au:N/C:P/I:P/A:P
3.9
6.4
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Operating System | watchguard | ap200_firmware | < 1.2.9.15 | Yes |
| Hardware | watchguard | ap200 | - | No |
| Operating System | watchguard | ap102_firmware | < 1.2.9.15 | Yes |
| Hardware | watchguard | ap102 | - | No |
| Operating System | watchguard | ap100_firmware | < 1.2.9.15 | Yes |
| Hardware | watchguard | ap100 | - | No |