---
id: CVE-2024-6592
title: >-
  An incorrect authorization vulnerability in the protocol communication between
  the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows
  and the WatchGuard Single Sign-On Client on Windows and MacOS allows an
  attacker w…
summary: >-
  An incorrect authorization vulnerability in the protocol communication between
  the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows
  and the WatchGuard Single Sign-On Client on Windows and MacOS allows an
  attacker w…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-306
  - CWE-863
vendor: watchguard
product: authentication_gateway
affected:
  - authentication_gateway <= 12.10.2
  - single_sign-on_client <= 12.5.4
  - single_sign-on_client <= 12.7
published: '2024-09-25'
updated: '2026-08-08'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-6592'
references:
  - url: 'https://psirt.watchguard.com/CVE-2024-6592'
    label: 5d1c2695-1a31-4499-88ae-e847036fd7e3
  - url: 'https://www.redteam-pentesting.de/advisories/rt-sa-2024-006'
    label: 5d1c2695-1a31-4499-88ae-e847036fd7e3
  - url: 'https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2024-00014'
    label: 5d1c2695-1a31-4499-88ae-e847036fd7e3
tags:
  - nvd
  - exploit-available
epss: 0.01158
epssPercentile: 0.65735
ingestedAt: '2026-08-08T00:19:07.445Z'
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/RedTeamPentesting/watchguard-sso-client'
  checkedAt: '2026-09-24T07:52:51.954Z'
exploitAvailable: true
---

## Overview

An incorrect authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows and the WatchGuard Single Sign-On Client on Windows and MacOS allows an attacker with network access to forge communications to affected components.

In the event an attacker has already gained network access, they could exploit this vulnerability to retrieve authenticated usernames and group memberships from the Single Sign-On Agent or send arbitrary account and group information to the Single Sign-On Agent for their host. This vulnerability cannot be used by an attacker to gain access to user credentials.

## Affected

- `authentication_gateway <= 12.10.2`
- `single_sign-on_client <= 12.5.4`
- `single_sign-on_client <= 12.7`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
