CVE-2024-6594

Summary

Improper Handling of Exceptional Conditions vulnerability in the WatchGuard Single Sign-On Client on Windows causes the client to crash while handling malformed commands. An attacker with network access to the client could create a denial of service condition for the Single Sign-On service by repeatedly issuing malformed commands.

Affected Software

VendorProductVersion RangeStatus
WatchGuardSSO Client12.0 <= 12.7affected

Weaknesses

  • CWE-755: CWE-755

Workarounds

An attacker must have already established network access to exploit this vulnerability. WatchGuard recommends using Windows Firewall rules to restrict TCP port 4116 network access to the Single Sign-On Client to only allow connections from the Authentication Gateway (SSO Agent). Windows administrators can use Group Policy objects to add Windows firewall rules to their endpoints.

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: yes
    • Technical Impact: partial

References