n authentication bypass vulnerability in Skyhigh SWG in main releases 10.x prior to 10.2.12, 9.x prior to 9.2.23, 8.x prior to 8.2.28, and controlled release 11.x prior to 11.2.1 allows a remote attacker to bypass authentication into the administration User Interface. This is possible because of SWG incorrectly whitelisting authentication bypass methods and using a weak crypto password. This can lead to the attacker logging into the SWG admin interface, without valid credentials, as the super user with complete control over the SWG.
Configuration 1 (hide)
|
21 Nov 2024, 07:00
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://kcm.trellix.com/corporate/index?page=content&id=SB10384&actp=null&viewlocale=en_US&showDraft=false&platinum_status=false&locale=en_US - Vendor Advisory | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 10.0 |
Published : 2022-07-27 10:15
Updated : 2024-11-21 07:00
NVD link : CVE-2022-2310
Mitre link : CVE-2022-2310
CVE.ORG link : CVE-2022-2310
JSON object : View
Authentication Bypass by Spoofing