skyhighsecurity records
4 published records for vendor skyhighsecurity.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 0%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-200 Exposure of Sensitive Information to an Unauthorized Actor1
- CWE-256 Plaintext Storage of a Password1
- CWE-290 Authentication Bypass by Spoofing1
- CWE-670 Always-Incorrect Control Flow Implementation1
The weakness classes this vendor ships most often: where to look.
CWEAttack profile
All records
4 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
39Monitor | CVE-2022-2310No exploit | Skyhigh SWG Authentication bypass vulnerabilityskyhighsecurity · secure web gateway · CWE-290 | Critical9.8 | — | 1.2% | Jul 27, 2022 |
26Monitor | CVE-2023-4400No exploit | A password management vulnerability in Skyhigh Secure Web Gateway (SWG) in main releases 11.x prior to 11.2.14, 10.x prior to 10.2.25 and cskyhighsecurity · secure web gateway · CWE-256 | Medium6.5 | — | 0.4% | Sep 13, 2023 |
22Monitor | CVE-2024-0313No exploit | A malicious insider exploiting this vulnerability can circumvent existing security controls put in place by the organization.skyhigh · skyhigh client proxy · CWE-670 | Medium5.5 | — | 0.2% | Mar 14, 2024 |
21Monitor | CVE-2024-6398No exploit | An information disclosure vulnerability in SWG in versions 12.x prior to 12.2.10 and 11.x prior to 11.2.24 allows information stored in a cuskyhighsecurity · secure web gateway · CWE-200 | Medium5.3 | — | 0.3% | Jul 15, 2024 |
- CVE-2022-231039Monitor
Skyhigh SWG Authentication bypass vulnerability
CriticalCVSS 9.8No exploitEPSS 1%skyhighsecurity · secure web gatewayJul 27, 2022
- CVE-2023-440026Monitor
A password management vulnerability in Skyhigh Secure Web Gateway (SWG) in main releases 11.x prior to 11.2.14, 10.x prior to 10.2.25 and c
MediumCVSS 6.5No exploitEPSS 0%skyhighsecurity · secure web gatewaySep 13, 2023
- CVE-2024-031322Monitor
A malicious insider exploiting this vulnerability can circumvent existing security controls put in place by the organization.
MediumCVSS 5.5No exploitEPSS 0%skyhigh · skyhigh client proxyMar 14, 2024
- CVE-2024-639821Monitor
An information disclosure vulnerability in SWG in versions 12.x prior to 12.2.10 and 11.x prior to 11.2.24 allows information stored in a cu
MediumCVSS 5.3No exploitEPSS 0%skyhighsecurity · secure web gatewayJul 15, 2024