CVE Database
/

CVE-2023-4400

Back to search

CVE-2023-4400

Published: Sep 13, 2023

Modified: Sep 25, 2024

PUBLISHED

CVSS v3.1

6.2

MEDIUM

Description

A password management vulnerability in Skyhigh Secure Web Gateway (SWG) in main releases 11.x prior to 11.2.14, 10.x prior to 10.2.25 and controlled release 12.x prior to 12.2.1, allows some authentication information stored in configuration files to be extracted through SWG REST API. This was possible due to SWG storing the password in plain text in some configuration files.

VendorProductVersions

Skyhigh Security

Skyhigh Secure Web Gateway (SWG)

affected
11.x - < 11.2.14
affected
10.x - < 10.2.25
affected
12.x - < 12.2.1

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:N/A:N

Attack Vector

Network

Attack Complexity

Low

Privileges Required

High

User Interaction

Required

Scope

Changed

Confidentiality

High

Integrity

None

Availability

None

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now