CVE-2022-2310
Last modified
CVE-2022-2310 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. An authentication bypass vulnerability in Skyhigh SWG in main releases 10.x prior to 10.2.12, 9.x prior to 9.2.23, 8.x prior to 8.2.28, and controlled release 11.x prior to 11.2.1 allows a remote attacker to bypass authentication into the administration User Interface. This is possible because of SWG incorrectly whitelisting authentication bypass methods and using a weak crypto password. EPSS estimates a 1.01% chance of exploitation in the next 30 days.
Description
An authentication bypass vulnerability in Skyhigh SWG in main releases 10.x prior to 10.2.12, 9.x prior to 9.2.23, 8.x prior to 8.2.28, and controlled release 11.x prior to 11.2.1 allows a remote attacker to bypass authentication into the administration User Interface. This is possible because of SWG incorrectly whitelisting authentication bypass methods and using a weak crypto password. This can lead to the attacker logging into the SWG admin interface, without valid credentials, as the super user with complete control over the SWG.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Skyhighsecurity | Secure Web Gateway | >= 8.0.0, < 8.2.28 |
| Skyhighsecurity | Secure Web Gateway | >= 9.0.0, < 9.2.23 |
| Skyhighsecurity | Secure Web Gateway | >= 10.0.0, < 10.2.12 |
| Skyhighsecurity | Secure Web Gateway | >= 11.0.0, < 11.2.1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-2310?
How severe is CVE-2022-2310?
How do I fix CVE-2022-2310?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-23094Libreswan 4.2 through 4.5 allows remote attackers to cause a…7.5
- CVE-2022-23095Open Design Alliance Drawings SDK before 2022.12.1 mishandle…7.8
- CVE-2022-23096An issue was discovered in the DNS proxy in Connman through …9.1
- CVE-2022-23097An issue was discovered in the DNS proxy in Connman through …9.1
- CVE-2022-23098An issue was discovered in the DNS proxy in Connman through …7.5
- CVE-2022-23099OX App Suite through 7.10.6 allows XSS by forcing block-wise…5.4
- CVE-2022-23100OX App Suite through 7.10.6 allows OS Command Injection via …9.8
- CVE-2022-23101OX App Suite through 7.10.6 allows XSS via appHandler in a d…6.1
- CVE-2022-23102A vulnerability has been identified in SINEMA Remote Connect…6.1
- CVE-2022-23103A stack-based buffer overflow vulnerability exists in the co…9.8
- CVE-2022-23104WIN-911 2021 R1 and R2 are vulnerable to a permissions misco…7.8
- CVE-2022-23105Jenkins Active Directory Plugin 2.25 and earlier does not en…6.5
Are you affected by CVE-2022-2310?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
