An authentication bypass vulnerability in Skyhigh SWG in main releases 10.x prior to 10.2.12, 9.x prior to 9.2.23, 8.x prior to 8.2.28, and controlled release 11.x prior to 11.2.1 allows a remote attacker to bypass authentication into the administration User Interface. This is possible because of SWG incorrectly whitelisting authentication bypass methods and using a weak crypto password. This can lead to the attacker logging into the SWG admin interface, without valid credentials, as the super user with complete control over the SWG.
                
            References
                    Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    21 Nov 2024, 07:00
| Type | Values Removed | Values Added | 
|---|---|---|
| CVSS | v2 : v3 : | v2 : unknown v3 : 10.0 | 
| References | () https://kcm.trellix.com/corporate/index?page=content&id=SB10384&actp=null&viewlocale=en_US&showDraft=false&platinum_status=false&locale=en_US - Vendor Advisory | 
02 Aug 2022, 18:25
| Type | Values Removed | Values Added | 
|---|---|---|
| CPE | cpe:2.3:a:skyhighsecurity:secure_web_gateway:*:*:*:*:*:*:*:* | |
| CVSS | v2 : v3 : | v2 : unknown v3 : 9.8 | 
| References | (CONFIRM) https://kcm.trellix.com/corporate/index?page=content&id=SB10384&actp=null&viewlocale=en_US&showDraft=false&platinum_status=false&locale=en_US - Vendor Advisory | 
27 Jul 2022, 10:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2022-07-27 10:15
Updated : 2024-11-21 07:00
NVD link : CVE-2022-2310
Mitre link : CVE-2022-2310
CVE.ORG link : CVE-2022-2310
JSON object : View
Products Affected
                skyhighsecurity
- secure_web_gateway
CWE
                
                    
                        
                        CWE-290
                        
            Authentication Bypass by Spoofing
