nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2020-10532 CVE-2020-10532
HIGHNuclei
WatchGuard Fireware AD Helper Component - Credentials Disclosure
Record summary
CVE-2020-10532 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
The AD Helper component in WatchGuard Fireware before 5.8.5.10317 allows remote attackers to discover cleartext passwords via the /domains/list URI.
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryCRITICALWatchGuard Fireware AD Helper Component - Credentials DisclosureCVSS 10
WatchGuard Fireware Threat Detection and Response (TDR) service contains a credential-disclosure vulnerability in the AD Helper component that allows unauthenticated attackers to gain Active Directory credentials for a Windows domain in plaintext.
Impact
Remote attackers can retrieve cleartext passwords, leading to potential account compromise and further system exploitation.
Remediation
Update to version 5.8.5.10317 or later.
WeaknessesCWE-288
Authorsgy741
Template tagscvecve2020watchguarddisclosureedbvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
https://nvd.nist.gov/vuln/detail/CVE-2020-10532 https://www.exploit-db.com/exploits/48203 https://www.watchguard.com/wgrd-blog/tdr-ad-helper-credential-disclosure-vulnerability
Source: ProjectDiscovery
References
3redteam-pentesting.de
https://www.redteam-pentesting.de/en/advisories/rt-sa-2020-001/-credential-disclosure-in-watchguard-fireware-ad-helper-component watchguard.com
https://www.watchguard.com/help/docs/help-center/en-US/Content/en-US/Fireware/services/tdr/tdr_ad_helper_c.html