Record summary

CVE-2020-10532 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.

Description

The AD Helper component in WatchGuard Fireware before 5.8.5.10317 allows remote attackers to discover cleartext passwords via the /domains/list URI.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryCRITICALWatchGuard Fireware AD Helper Component - Credentials DisclosureCVSS 10

WatchGuard Fireware Threat Detection and Response (TDR) service contains a credential-disclosure vulnerability in the AD Helper component that allows unauthenticated attackers to gain Active Directory credentials for a Windows domain in plaintext.

Impact

Remote attackers can retrieve cleartext passwords, leading to potential account compromise and further system exploitation.

Remediation

Update to version 5.8.5.10317 or later.

WeaknessesCWE-288
Authorsgy741
Template tagscvecve2020watchguarddisclosureedbvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Source: ProjectDiscovery

References

3