CVE-2024-6594

WatchGuard Firebox Single Sign-On Client Denial-of-Service

High 8.7 CVSS v4.0 › Published 2024-09-25Updated 2026-08-07

Summary #

Improper Handling of Exceptional Conditions vulnerability in the WatchGuard Single Sign-On Client on Windows causes the client to crash while handling malformed commands. An attacker with network access to the client could create a denial of service condition for the Single Sign-On service by repeatedly issuing malformed commands.

Product status #

ProductAffectedNot affected
SSO Client
Windows >= 12.0, <= 12.7> 12.7

Weakness Type and Impact #

  • CWECWE-755Improper Handling of Exceptional Conditions
  • CAPECCAPEC-227Sustained Client Engagement

Exploitation Status #

WatchGuard is not aware of any exploitation of this vulnerability in the wild.

Solution #

Update to a fixed release per the affected-version ranges above.

Workaround #

An attacker must have already established network access to exploit this vulnerability. WatchGuard recommends using Windows Firewall rules to restrict TCP port 4116 network access to the Single Sign-On Client to only allow connections from the Authentication Gateway (SSO Agent). Windows administrators can use Group Policy objects to add Windows firewall rules to their endpoints.

References #

Credits #

  • Found by RedTeam Pentesting GmbH finder