CVE-2023-4400

A password management vulnerability in Skyhigh Secure Web Gateway (SWG) in main releases 11.x prior to 11.2.14, 10.x prior to 10.2.25 and controlled release 12.x prior to 12.2.1, allows some authentication information stored in configuration files to be extracted through SWG REST API. This was possible due to SWG storing the password in plain text in some configuration files.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:skyhighsecurity:secure_web_gateway:*:*:*:*:*:*:*:*
cpe:2.3:a:skyhighsecurity:secure_web_gateway:*:*:*:*:*:*:*:*
cpe:2.3:a:skyhighsecurity:secure_web_gateway:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2023-09-13 07:15

Updated : 2023-09-15 19:21


NVD link : CVE-2023-4400

Mitre link : CVE-2023-4400

CVE.ORG link : CVE-2023-4400


JSON object : View

Products Affected

skyhighsecurity

  • secure_web_gateway
CWE
CWE-312

Cleartext Storage of Sensitive Information

CWE-256

Plaintext Storage of a Password