CVE-2023-4400 - CVE House
Back to Database
Status published Medium CVE-2023-4400

A password management vulnerability in Skyhigh Secure Web Gateway (SWG)...

Vulnerability Description

A password management vulnerability in Skyhigh Secure Web Gateway (SWG) in main releases 11.x prior to 11.2.14, 10.x prior to 10.2.25 and controlled release 12.x prior to 12.2.1, allows some authentication information stored in configuration files to be extracted through SWG REST API. This was possible due to SWG storing the password in plain text in some configuration files.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-4400

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Skyhigh Security

View all reports →

Affected Software

Skyhigh Secure Web Gateway (SWG)
Vulnerable Versions:
11.x, 10.x, 12.x

Timeline

Official Publish: September 13th, 2023
Last Modified: September 25th, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:N/A:N

Weaknesses (CWE)