Back

HIGH

WatchGuard Firebox Single Sign-On Client Denial-of-Service

Published Sep 25, 2024

Description

Improper Handling of Exceptional Conditions vulnerability in the WatchGuard Single Sign-On Client on Windows causes the client to crash while handling malformed commands. An attacker with network access to the client could create a denial of service condition for the Single Sign-On service by repeatedly issuing malformed commands.

Affected products

Remediation

Vendor solution

An attacker must have already established network access to exploit this vulnerability. WatchGuard recommends using Windows Firewall rules to restrict TCP port 4116 network access to the Single Sign-On Client to only allow connections from the Authentication Gateway (SSO Agent). Windows administrators can use Group Policy objects to add Windows firewall rules to their endpoints.

Weaknesses (1)

References (4)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner WatchGuard
Published Sep 25, 2024
Updated Aug 7, 2026
Reserved Jul 9, 2024
CISA Vulnrichment
Updated Sep 25, 2024
NVD
Status Modified
Modified Aug 8, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner WatchGuard
Published Sep 25, 2024
Updated Aug 7, 2026
Exploited since n/a
EUVD-2024-47659