Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2018-10578


An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15, and AP300 devices with firmware before 2.0.0.10. Incorrect validation of the "old password" field in the change password form allows an attacker to bypass validation of this field.


Published

2018-05-02T21:29:01.043

Last Modified

2024-11-21T03:41:35.967

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 9.8 (CRITICAL)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-20

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System watchguard ap200_firmware < 1.2.9.15 Yes
Hardware watchguard ap200 - No
Operating System watchguard ap102_firmware < 1.2.9.15 Yes
Hardware watchguard ap102 - No
Operating System watchguard ap100_firmware < 1.2.9.15 Yes
Hardware watchguard ap100 - No
Operating System watchguard ap300_firmware < 2.0.0.10 Yes
Hardware watchguard ap300 - No

References