NA

CVE-2022-2310

Published: 27/07/2022 Updated: 15/11/2023
CVSS v3 Base Score: 9.8 | Impact Score: 5.9 | Exploitability Score: 3.9
VMScore: 0

Vulnerability Summary

An authentication bypass vulnerability in Skyhigh SWG in main releases 10.x before 10.2.12, 9.x before 9.2.23, 8.x before 8.2.28, and controlled release 11.x before 11.2.1 allows a remote malicious user to bypass authentication into the administration User Interface. This is possible because of SWG incorrectly whitelisting authentication bypass methods and using a weak crypto password. This can lead to the attacker logging into the SWG admin interface, without valid credentials, as the super user with complete control over the SWG.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

skyhighsecurity secure web gateway