CVE-2018-10578
Summary
| CVE | CVE-2018-10578 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2018-05-02 21:29:00 UTC |
| Updated | 2018-06-13 14:09:00 UTC |
| Description | An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15, and AP300 devices with firmware before 2.0.0.10. Incorrect validation of the "old password" field in the change password form allows an attacker to bypass validation of this field. |
Risk And Classification
Problem Types: CWE-20
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Hardware | Watchguard | Ap100 | - | All | All | All |
| Hardware | Watchguard | Ap100 | - | All | All | All |
| Operating System | Watchguard | Ap100 Firmware | All | All | All | All |
| Operating System | Watchguard | Ap100 Firmware | All | All | All | All |
| Hardware | Watchguard | Ap102 | - | All | All | All |
| Hardware | Watchguard | Ap102 | - | All | All | All |
| Operating System | Watchguard | Ap102 Firmware | All | All | All | All |
| Operating System | Watchguard | Ap102 Firmware | All | All | All | All |
| Hardware | Watchguard | Ap200 | - | All | All | All |
| Hardware | Watchguard | Ap200 | - | All | All | All |
| Operating System | Watchguard | Ap200 Firmware | All | All | All | All |
| Operating System | Watchguard | Ap200 Firmware | All | All | All | All |
| Hardware | Watchguard | Ap300 | - | All | All | All |
| Hardware | Watchguard | Ap300 | - | All | All | All |
| Operating System | Watchguard | Ap300 Firmware | All | All | All | All |
| Operating System | Watchguard | Ap300 Firmware | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Full Disclosure: Multiple issues in WatchGuard AP100 AP102 AP200 result in remote code execution | FULLDISC | seclists.org | Mailing List, Third Party Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.