---
id: CVE-2024-6593
title: >-
  Incorrect Authorization vulnerability in WatchGuard Authentication Gateway
  (aka Single Sign-On Agent) on Windows allows an attacker with network access
  to execute restricted management commands.


  An attacker that has already gained netwo…
summary: >-
  Incorrect Authorization vulnerability in WatchGuard Authentication Gateway
  (aka Single Sign-On Agent) on Windows allows an attacker with network access
  to execute restricted management commands.


  An attacker that has already gained netwo…
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-863
  - CWE-863
vendor: watchguard
product: authentication_gateway
affected:
  - authentication_gateway <= 12.10.2
published: '2024-09-25'
updated: '2026-08-08'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2024-6593'
references:
  - url: 'https://psirt.watchguard.com/CVE-2024-6593'
    label: 5d1c2695-1a31-4499-88ae-e847036fd7e3
  - url: 'https://www.redteam-pentesting.de/advisories/rt-sa-2024-007'
    label: 5d1c2695-1a31-4499-88ae-e847036fd7e3
  - url: 'https://www.watchguard.com/wgrd-psirt/advisory/wgsa-2024-00015'
    label: 5d1c2695-1a31-4499-88ae-e847036fd7e3
tags:
  - nvd
epss: 0.00579
epssPercentile: 0.46377
ingestedAt: '2026-08-08T00:19:07.508Z'
---

## Overview

Incorrect Authorization vulnerability in WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows allows an attacker with network access to execute restricted management commands.

An attacker that has already gained network access could exploit this vulnerability to retrieve authenticated usernames and group memberships from the Single Sign-On Agent or tamper with the agent configuration. This vulnerability cannot be used by an attacker to gain access to user credentials.

## Affected

- `authentication_gateway <= 12.10.2`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
