Weekly digest
Week 39, 2024 (23–29 Sep)
8 new CVEs this week, in line with the recent average. Severity skewed high: 3 critical and 3 high, 75% of the total. 2 arrived with exploitation evidence or public exploit code already attached. No new KEV entries. watchguard was the most-affected vendor with 3.
New this week, ranked by depth score
The 8 that matter most of the 8 published.
CVE-2024-6592Critical· 9.1PoCAn incorrect authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows and the WatchGuard Single Sign-On Client on Windows and MacOS allows an attacker w…
An incorrect authorization vulnerability in the protocol communication between the WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows and the WatchGuard Single Sign-On Client on Windows and MacOS allows an attacker w…
CVE-2024-9014High· 8.6PoCOAuth2 client ID and secret exposed through the web browser
OAuth2 client ID and secret exposed through the web browser
CVE-2024-6593Critical· 9.1Incorrect Authorization vulnerability in WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows allows an attacker with network access to execute restricted management commands. An attacker that has already gained netwo…
Incorrect Authorization vulnerability in WatchGuard Authentication Gateway (aka Single Sign-On Agent) on Windows allows an attacker with network access to execute restricted management commands. An attacker that has already gained netwo…
CVE-2024-46488Critical· 9.1Heap-based Buffer Overflow in sqlite-vec
Heap-based Buffer Overflow in sqlite-vec
CVE-2024-7594High· 7.5Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default
Vault SSH Secrets Engine Configuration Did Not Restrict Valid Principals By Default
CVE-2024-6594High· 7.5Improper Handling of Exceptional Conditions vulnerability in the WatchGuard Single Sign-On Client on Windows causes the client to crash while handling malformed commands
Improper Handling of Exceptional Conditions vulnerability in the WatchGuard Single Sign-On Client on Windows causes the client to crash while handling malformed commands. An attacker with network access to the client could create a denia…
CVE-2024-47003Medium· 5.4Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events
Mattermost fails to strip `embeds` from `metadata` when broadcasting `posted` events
CVE-2024-9277Low· 3.5Inefficient Regular Expression Complexity in langflow
Inefficient Regular Expression Complexity in langflow
Most-affected vendors
By CVEs published in the period.